vendor:
Service Desk
by:
Pedro Ribeiro
7.2
CVSS
HIGH
Arbitrary file upload via directory traversal (leading to remote code execution)
22
CWE
Product Name: Service Desk
Affected Version From: 7.1.2000
Affected Version To: 6.5
Patch Exists: NO
Related CWE: CVE-2016-1593
CPE: a:novell:service_desk:7.1.0 cpe:/a:novell:service_desk:7.0.3 cpe:/a:novell:service_desk:6.5
Platforms Tested: Unknown
2016
Multiple vulnerabilities in Novell Service Desk 7.1.0, 7.0.3 and 6.5
Novell Service Desk has several vulnerabilities including a file upload function that can be exploited to achieve authenticated remote code execution. The product appears to be a rebranded version of Absolute Service (another help desk system). The latter has not been tested but it is likely to contain the same vulnerabilities as Novell Service Desk.
Mitigation:
Unknown