>> HP Info Center Command Execution and Registry Manipulation Issues
Title : HP Info Center Command Execution and Registry Manipulation Issues VUPEN ID : VUPEN/ADV-2007-4192 CVE ID : CVE-2007-6331 - CVE-2007-6332 - CVE-2007-6333
Rated as : Critical
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-12-12
Technical Description
Multiple vulnerabilities have been identified in HP Quick Launch Button, which could be exploited by remote attackers to disclose and manipulate sensitive information, or take complete control of an affected system. These issues are caused by errors in the "HPInfoDLL.dll" ActiveX control that includes the insecure methods "LaunchApp()", "GetRegValue()" and "SetRegValue()", which could be exploited by attackers to execute arbitrary commands or read and write registry data by tricking a user into visiting a malicious web page.