vendor:
HP LoadRunner
by:
Unknown, aushack
7.5
CVSS
HIGH
Remote Command Execution
Unknown
CWE
Product Name: HP LoadRunner
Affected Version From: HP LoadRunner before 9.50 and HP Performance Center before 9.50
Affected Version To: HP LoadRunner 12.53 (non-default SSL option turned off)
Patch Exists: NO
Related CWE: CVE-2010-1549
CPE: a:hp:loadrunner:9.50
Platforms Tested: Windows
2010
HP Mercury LoadRunner Agent magentproc.exe Remote Command Execution
This module exploits a remote command execution vulnerablity in HP LoadRunner before 9.50 and also HP Performance Center before 9.50. HP LoadRunner 12.53 and other versions are also most likely vulneable if the (non-default) SSL option is turned off. By sending a specially crafted packet, an attacker can execute commands remotely. The service is vulnerable provided the Secure Channel feature is disabled (default).
Mitigation:
Enable the Secure Channel feature or update to a patched version.