APP:ZENworks Handheld Management File Upload
This signature detects attempts to exploit a known vulnerability against Novell ZENworks Handheld Management. Versions 7.0.2.61213 and 7 are vulnerable. Attackers can upload arbitrary files to the affected system.
Extended Description
Novell ZENworks Handheld Management is prone to a directory-traversal vulnerability in the 'ZfHSrvr.exe' service because it fails to sufficiently sanitize user-supplied input. Exploiting this issue can allow an attacker to upload arbitrary files to the affected system. ZENworks Handheld Management 7.0.2.61213 and prior are vulnerable; other versions may also be affected.
Affected Products
Novell zenworks_handheld_management
srx-branch-12.3
srx-19.3
srx-branch-19.3
vsrx3bsd-19.2
srx-branch-19.4
vsrx-19.4
mx-12.3
mx-19.4
vmx-19.4
mx-19.3
vsrx3bsd-19.4
srx-19.4
vsrx-12.3
vmx-19.3
vsrx-19.2
srx-12.3
Novell