peter bassill · operator
$ cve CVE-2007-6506 JSON

CVE-2007-6506 EXPLOIT

9.3
HIGH · CVSS 2.0 · EPSS 16.3% (pctl 97)

Patch early

A public exploit exists.

Description

The HPRulesEngine.ContentCollection.1 ActiveX Control in RulesEngine.dll for HP Software Update 4.000.005.007 and earlier, including 3.0.8.4, allows remote attackers to (1) overwrite and corrupt arbitrary files via arguments to the SaveToFile method, and possibly (2) access arbitrary files via the LoadDataFromFile method.

Scoring

CVSS9.3 (HIGH, v2.0)
VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS16.35% — more likely to be exploited than 97% of all CVEs
On CISA KEVno
Public exploityes
Published2007-12-20
Last modified2026-06-16

Affected (1)

VendorProduct
hpsoftware update

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD