HP.LoadRunner.XUpload.MakeHttpRequest

NameHP.LoadRunner.XUpload.MakeHttpRequest.ActiveX.Control.Access
Release DateDec 29, 2009
SeverityCritical
ImpactSystem Compromise
Security Bypass
DescriptionThis indicates an attack attempt against an arbitrary file download and execute vulnerability in HP LoadRunner.

The vulnerability is caused by an error when the Persits.XUpload ActiveX control handles a specially crafted web page. It allows a remote attacker to overwrite credential files on the target system.
Affected ProductsHP Mercury LoadRunner Agent 9.5
Recommended ActionsSet the kill bit for the CLSID {E87F6C8E-16C0-11D3-BEF7-009027438003}.
Common Vulnerabilities and Exposures (CVE)http://cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3693
Reference/shttp://www.securityfocus.com/bid/36550 (BugTraq)
http://retrogod.altervista.org/9sg_hp_loadrunner.html
Reference: VID-17986