HP Easy Printer Care CacheDocumentXMLWithID ActiveX Control Directory Traversal

Strike ID:
E11-6oy01
CVSS:
9.3 (AV:N/AC:M/Au:N/C:C/I:C/A:C)
False Positive:
f
Variants:
4
Year:
2011

Description

HP Easy Printer Care Software contains a directory traversal vulnerability. The flaw is due to a lack of input validation by the CacheDocumentXMLWithId method. An attacker could exploit this vulnerablity to create and/or overwrite files, resulting in a denial of service or remote code execution.

CVE

References

Bid