Novell ZENworks Configuration Management CVE-2013-3706 Directory Traversal Vulnerability
BID:65912
Info
Novell ZENworks Configuration Management CVE-2013-3706 Directory Traversal Vulnerability
| Bugtraq ID: | 65912 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-3706 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 28 2014 12:00AM |
| Updated: | Apr 08 2014 03:49PM |
| Credit: | Mak Kolybabi |
| Vulnerable: |
Novell ZENworks Configuration Management 11.2 |
| Not Vulnerable: | |
Discussion
Novell ZENworks Configuration Management CVE-2013-3706 Directory Traversal Vulnerability
Novell ZENworks Configuration Management is prone to a directory-traversal vulnerability because it fails to properly sanitize user-supplied input.
Exploiting this issue may allow an attacker to obtain sensitive information that could aid in further attacks.
Novell ZENworks Configuration Management 11.2 is vulnerable.
Novell ZENworks Configuration Management is prone to a directory-traversal vulnerability because it fails to properly sanitize user-supplied input.
Exploiting this issue may allow an attacker to obtain sensitive information that could aid in further attacks.
Novell ZENworks Configuration Management 11.2 is vulnerable.
Exploit / POC
Novell ZENworks Configuration Management CVE-2013-3706 Directory Traversal Vulnerability
Attackers can exploit this issue with a web browser or readily available tools.
Attackers can exploit this issue with a web browser or readily available tools.
Solution / Fix
Novell ZENworks Configuration Management CVE-2013-3706 Directory Traversal Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Novell ZENworks Configuration Management CVE-2013-3706 Directory Traversal Vulnerability
References:
References:
- Novell Homepage (Novell)