HP LoadRunner Web Tours "login.pl" Directory Traversal Vulnerability
Description
A vulnerability has been identified in HP LoadRunner, which could be exploited by remote attackers to cause a denial of service or execute arbitrary code. This issue is caused by an input validation error in the "login.pl" script within Web Tours when processing usernames, which could allow remote attackers to create arbitrary files ona vulnerable system via directory traversal attacks and cause a denial of service or compromise a vulnerable system.
Vulnerable Products
Vulnerable Software: HP LoadRunner version 9.1 and prior