vendor:
ZENworks Asset Management
by:
Unknown, juan vazquez
N/A
CVSS
N/A
Path Traversal
22
CWE
Product Name: ZENworks Asset Management
Affected Version From: 7.5
Affected Version To: 7.5
Patch Exists: YES
Related CWE: CVE-2011-2653
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Java
2011
Novell ZENworks Asset Management Remote Execution
This module exploits a path traversal flaw in Novell ZENworks Asset Management 7.5. By exploiting the CatchFileServlet, an attacker can upload a malicious file outside of the MalibuUploadDirectory and then make a secondary request that allows for arbitrary code execution.
Mitigation:
Novell has released a patch to address this vulnerability.