APP: Novell ZENworks Management Language Parameter Directory Traversal

This signature detects attempts to exploit a known vulnerability against Novell ZENworks Mobile Management server. A successful attack can lead to arbitrary code execution.

Extended Description

Directory traversal vulnerability in MDM.php in Novell ZENworks Mobile Management (ZMM) 2.6.1 and 2.7.0 allows remote attackers to include and execute arbitrary local files via the language parameter.

Affected Products

Novell zenworks_mobile_management

Short Name
APP:NOVELL:ZENWORKS-LG-DIR-TRAV
Severity
Critical
Recommended
True
Recommended Action
Drop
Category
APP
Keywords
CVE-2013-1081 CVE-2013-1082 Directory Language Management Novell Parameter Traversal ZENworks bid:58402 bid:60179
Release Date
03/28/2024
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3690
False Positive
Unknown
Vendors

Novell

CVSS Score

7.5

Found a potential security threat?