← back
CVE-2009-3693

CVE-2009-3693

50Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 42%
from disclosure to weapon0 days
Published on NVDOct 13
1st PoCSep 29
metasploitSep 29
exploitation probability
42%top 1% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
Directory traversal vulnerability in the Persits.XUpload.2 ActiveX control (XUpload.ocx) in HP LoadRunner 9.5 allows remote attackers to create arbitrary files via \.. (backwards slash dot dot) sequences in the third argument to the MakeHttpRequest method.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.