Critical severity9.1NVD Advisory· Published Jun 8, 2016· Updated May 6, 2026
CVE-2016-4360
CVE-2016-4360
Description
web/admin/data.js in the Performance Center Virtual Table Server (VTS) component in HPE LoadRunner 11.52 through patch 3, 12.00 through patch 1, 12.01 through patch 3, 12.02 through patch 2, and 12.50 through patch 3 and Performance Center 11.52 through patch 3, 12.00 through patch 1, 12.01 through patch 3, 12.20 through patch 2, and 12.50 through patch 1 do not restrict file paths sent to an unlink call, which allows remote attackers to delete arbitrary files via the path parameter to data/import_csv, aka ZDI-CAN-3555.
Affected products
10cpe:2.3:a:hp:loadrunner:11.52:p3:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:hp:loadrunner:11.52:p3:*:*:*:*:*:*
- cpe:2.3:a:hp:loadrunner:12.00:p1:*:*:*:*:*:*
- cpe:2.3:a:hp:loadrunner:12.01:p3:*:*:*:*:*:*
- cpe:2.3:a:hp:loadrunner:12.02:p2:*:*:*:*:*:*
- cpe:2.3:a:hp:loadrunner:12.50:p3:*:*:*:*:*:*
cpe:2.3:a:hp:performance_center:11.52:p3:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:hp:performance_center:11.52:p3:*:*:*:*:*:*
- cpe:2.3:a:hp:performance_center:12.00:p1:*:*:*:*:*:*
- cpe:2.3:a:hp:performance_center:12.01:p3:*:*:*:*:*:*
- cpe:2.3:a:hp:performance_center:12.20:p2:*:*:*:*:*:*
- cpe:2.3:a:hp:performance_center:12.50:p1:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- www.securitytracker.com/id/1036006nvdThird Party AdvisoryVDB Entry
- www.zerodayinitiative.com/advisories/ZDI-16-364nvdThird Party AdvisoryVDB Entry
- h20566.www2.hpe.com/hpsc/doc/public/displaynvdVendor Advisory
- www.securityfocus.com/bid/90975nvd
- www.tenable.com/security/research/tra-2016-17nvd
News mentions
0No linked articles in our index yet.