Unrated severityNVD Advisory· Published Jun 18, 2014· Updated May 6, 2026
CVE-2013-6221
CVE-2013-6221
Description
Directory traversal vulnerability in CommunicationServlet in HP Service Virtualization 3.x before 3.50.1, when the AutoPass license server is enabled, allows remote attackers to create arbitrary files and consequently execute arbitrary code via unspecified vectors, aka ZDI-CAN-2031.
Affected products
1- cpe:2.3:a:hp:service_virtualization:3.0:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- h20564.www2.hp.com/portal/site/hpsc/public/kb/docDisplaynvdVendor Advisory
- packetstormsecurity.com/files/127247/HP-AutoPass-License-Server-File-Upload.htmlnvd
- www.exploit-db.com/exploits/33891nvd
- www.osvdb.org/107943nvd
- www.securitytracker.com/id/1030385nvd
- zerodayinitiative.com/advisories/ZDI-14-195/nvd
- github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/http/hp_autopass_license_traversal.rbnvd
News mentions
0No linked articles in our index yet.