VendorsHPmercury_quality_centerany version
Vulnerabilities

HP Mercury Quality Center any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1CVEs
CVE-2007-5289
HP Mercury Quality Center (QC) 9.2 and earlier, and possibly TestDirector, relies on cached client-side scripts to implement "workflow" and decisions about the "capability" of a user, which allows remote attackers to execute arbitrary code via crafted use of the Open Test Architecture (OTA) API, as demonstrated by modifying (1) common.tds, (2) defects.tds, (3) manrun.tds, (4) req.tds, (5) testlab.tds, or (6) testplan.tds in %tmp%\TD_80, and then setting the file's properties to read-only.
Published 2009-02-24 · Modified
7.6EPSS 0.087