Description
|
|
A vulnerability has been identified in HP Mercury Quality Center, which could be exploited by malicious users to execute arbitrary SQL queries. This issue is due to a design error in the "/qcbin/servlet/tdservlet/TDAPI_GeneralWebTreatment" script that does not restrict access to the "RunQuery" command, which could be exploited by authenticated attackers to execute arbitrary SQL queries on the underlying database server.
|