CVE-2016-1593
high · 7.2Directory traversal vulnerability in the import users feature in Micro Focus Novell Service Desk before 7.2 allows remote authenticated administrators to upload and execute arbitrary JSP files via a .. (dot dot) in a filename within a multipart/form-data POST request to a LiveTime.woa URL.
7.2
CVSS
64.1%
EPSS (exploit prob.)
99th
EPSS percentile
2016-04-22
Published
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-22
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| novell | service_desk | <= 7.1 |
Check a specific version with /api/v1/cve/match.
References
- http://packetstormsecurity.com/files/136717/Novell-ServiceDesk-Authenticated-File-Upload.html
- http://www.rapid7.com/db/modules/exploit/multi/http/novell_servicedesk_rce
- http://www.securityfocus.com/archive/1/538043/100/0/threaded
- https://packetstormsecurity.com/files/136646
- https://raw.githubusercontent.com/pedrib/PoC/master/advisories/novell-service-desk-7.1.0.txt
- https://www.exploit-db.com/exploits/39687/
- https://www.exploit-db.com/exploits/39708/
- https://www.novell.com/support/kb/doc.php?id=7017428
- http://packetstormsecurity.com/files/136717/Novell-ServiceDesk-Authenticated-File-Upload.html
- http://www.rapid7.com/db/modules/exploit/multi/http/novell_servicedesk_rce
- http://www.securityfocus.com/archive/1/538043/100/0/threaded
- https://packetstormsecurity.com/files/136646
- https://raw.githubusercontent.com/pedrib/PoC/master/advisories/novell-service-desk-7.1.0.txt
- https://www.exploit-db.com/exploits/39687/
- https://www.exploit-db.com/exploits/39708/
- https://www.novell.com/support/kb/doc.php?id=7017428
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2016-1593