vendor:
eSupportDiagnostics
by:
Unknown
7.5
CVSS
HIGH
Information Disclosure
200
CWE
Product Name: eSupportDiagnostics
Affected Version From: 1.0.11.0
Affected Version To: Unknown
Patch Exists: NO
Related CWE:
CPE: a:hp:esupportdiagnostics:1.0.11.0
Platforms Tested:
Unknown
HP eSupportDiagnostics ActiveX Control Information Disclosure Vulnerabilities
The HP eSupportDiagnostics ActiveX control is prone to multiple information-disclosure vulnerabilities. An attacker can exploit these issues by enticing an unsuspecting victim to visit a malicious HTML page. Successfully exploiting these issues allows remote attackers to obtain the contents of arbitrary files and registry values. Information harvested may aid in further attacks.
Mitigation:
Unknown