HTTP: HP LoadRunner WriteFileString Unsafe ActiveX Control

This signature detects attempts to use unsafe ActiveX controls in HP LoadRunner. An attacker can create a malicious Web site containing Web pages with dangerous ActiveX controls, which if accessed by a victim, allows the attacker to gain control of the victim's application.

Extended Description

Unspecified vulnerability in HP LoadRunner before 11.52 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1705.

Affected Products

Hp loadrunner

Short Name
HTTP:STC:ACTIVEX:WFILESTRING
Severity
Minor
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
ActiveX CVE-2013-4798 Control HP LoadRunner Unsafe WriteFileString bid:61443
Release Date
09/10/2013
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3668
False Positive
Unknown
Vendors

Hp

CVSS Score

10.0

Found a potential security threat?