Persits develops a narrow line of web-based file-upload components, primarily ASPUpload and XUpload, that handle user-supplied file submissions in legacy and contemporary web applications. The observed vulnerability pattern centers on memory-safety and path-traversal weaknesses endemic to file-handling logic, including buffer-boundary violations and directory-traversal conditions that arise when validating and storing uploaded content. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Persits over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2009-3693HIGH Directory traversal vulnerability in the Persits.XUpload.2 ActiveX control (XUpload.ocx) in HP LoadRunner 9.5 allows remote attackers to create arbitrary files via \.. (backwards s | Oct 13, 2009 | 9.3 | 66 | NO | YES |
CVE-2007-6530HIGH Buffer overflow in the XUpload.ocx ActiveX control in Persits Software XUpload 2.1.0.1, and probably other versions before 3.0, as used by HP Mercury LoadRunner and Groove Virtual | Dec 27, 2007 | 9.3 | 62 | NO | YES |
CVE-2008-0492MEDIUM Stack-based buffer overflow in the Persits.XUpload.2 ActiveX control in XUpload.ocx 3.0.0.4 and earlier in Persits XUpload 3.0 allows remote attackers to execute arbitrary code via | Jan 30, 2008 | 6.8 | 50 | NO | YES |
CVE-1999-1535HIGH Buffer overflow in AspUpload.dll in Persits Software AspUpload before 1.4.0.2 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a l | Jul 20, 1999 | 10.0 | 28 | NO | NO |
CVE-2001-0938MEDIUM Directory traversal vulnerability in AspUpload 2.1, in certain configurations, allows remote attackers to upload and read arbitrary files, and list arbitrary directories, via a .. | Nov 30, 2001 | 6.4 | 18 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Persits.
Media articles that mention a CVE ID that affects a product developed by Persits — matched by CVE ID, not by vendor name.