Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
HP Mercury Quality Center (QC) 9.2 and earlier, and possibly TestDirector, relies on cached client-side scripts to implement "workflow" and decisions about the "capability" of a user, which allows remote attackers to execute arbitrary code via crafted use of the Open Test Architecture (OTA) API, as demonstrated by modifying (1) common.tds, (2) defects.tds, (3) manrun.tds, (4) req.tds, (5) testlab.tds, or (6) testplan.tds in %tmp%\TD_80, and then setting the file's properties to read-only.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
HP Quality Center缓存工作流脚本绕过安全限制漏洞
Vulnerability Description
HP质量中心可管理和控制质量流程,并在IT和应用环境中实现软件测试自动化。 HP质量中心的前端有一些嵌入到WEB浏览器中的COM组件组成。质量中心提供了自定义功能(被称为工作流),允许管理员修改默认的行为。这个工作流是由VBScript函数驱动的,每当客户端前端出现特定的事件时就会调用这些函数。 为了优化应用程序的交互速度,会在客户端机器创建缓存文件夹,默认情况下位于%tmp%/TD_80。当用户连接到质量中心项目时,会用最新的VBScript工作流文件自动更新缓存文件夹,之后质量中心前端读取这些文件一次
CVSS Information
N/A
Vulnerability Type
N/A