header-logo
Suggest Exploit
vendor:
ZENworks Asset Management
by:
Unknown, juan vazquez
N/A
CVSS
N/A
Path Traversal
22
CWE
Product Name: ZENworks Asset Management
Affected Version From: 7.5
Affected Version To: 7.5
Patch Exists: YES
Related CWE: CVE-2011-2653
CPE: N/A
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: Java
2011

Novell ZENworks Asset Management Remote Execution

This module exploits a path traversal flaw in Novell ZENworks Asset Management 7.5. By exploiting the CatchFileServlet, an attacker can upload a malicious file outside of the MalibuUploadDirectory and then make a secondary request that allows for arbitrary code execution.

Mitigation:

Novell has released a patch to address this vulnerability.
Source

Exploit-DB raw data: