Executive Summary

Summary
Title HP LoadRunner Web Tours 9.10 Remote Denial of Service
Informations
Name HPSBMA02533 SSRT080049 First vendor Publication 2010-10-26
Vendor HP Last vendor Modification 2010-10-26
Severity (Vendor) N/A Revision 1

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:L/Au:N/C:P/I:P/A:P)
Cvss Base Score 7.5 Attack Range Network
Cvss Impact Score 6.4 Attack Complexity Low
Cvss Expoit Score 10 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

A potential vulnerability has been identified with HP LoadRunner Web Tours 9.10. The vulnerability could be remotely exploited to cause a denial of service.

Original Source

Url : http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c02165172

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 15
Application 1

Open Source Vulnerability Database (OSVDB)

Id Description
69338 HP LoadRunner LoadRunner Web Tours login.pl Username Specifier Traversal Arbi...

HP LoadRunner LoadRunner Web Tours contains a flaw that allows a remote attacker to traverse outside of a restricted path. The issue is due to the 'login.pl' script not properly sanitizing user input, specifically directory traversal style attacks (e.g., ../../) supplied via the 'username' parameter. This directory traversal attack would allow the attacker to upload arbitrary files.
69212 HP LoadRunner LoadRunner Web Tours Unspecified Remote DoS

HP LoadRunner contains a flaw related to LoadRunner Web Tours that may allow a remote attacker to cause a denial of service. No further details have been provided.