- EPSS 5.08%
- Veröffentlicht 02.11.2013 19:55:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
Directory traversal vulnerability in the GetFle method in the umaninv service in Novell ZENworks Configuration Management (ZCM) 11.2.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the Filename parameter in a GetFile action to...
CVE-2013-1097
- EPSS 1.3%
- Veröffentlicht 17.06.2013 11:38:49
- Zuletzt bearbeitet 11.04.2025 00:51:21
Cross-site scripting (XSS) vulnerability in a ZCC page in njwc.jar in Novell ZENworks Configuration Management (ZCM) 11.2 before 11.2.3a Monthly Update 1 allows remote attackers to inject arbitrary web script or HTML via vectors involving an onload e...
CVE-2013-1095
- EPSS 1.3%
- Veröffentlicht 17.06.2013 11:38:48
- Zuletzt bearbeitet 11.04.2025 00:51:21
Cross-site scripting (XSS) vulnerability in a ZCC page in njwc.jar in Novell ZENworks Configuration Management (ZCM) 11.2 before 11.2.3a Monthly Update 1 allows remote attackers to inject arbitrary web script or HTML via vectors involving an onError ...
CVE-2013-1094
- EPSS 2.36%
- Veröffentlicht 17.06.2013 11:38:48
- Zuletzt bearbeitet 11.04.2025 00:51:21
Cross-site scripting (XSS) vulnerability in a ZCC page in zenworks-core in Novell ZENworks Configuration Management (ZCM) 11.2 before 11.2.3a Monthly Update 1 allows remote attackers to inject arbitrary web script or HTML via an invalid locale.
CVE-2013-1093
- EPSS 2.02%
- Veröffentlicht 17.06.2013 11:38:48
- Zuletzt bearbeitet 11.04.2025 00:51:21
Open redirect vulnerability in the fwdToURL function in the ZCC login page in zcc-framework.jar in Novell ZENworks Configuration Management (ZCM) 11.2 before 11.2.3a Monthly Update 1 allows remote attackers to redirect users to arbitrary web sites an...
- EPSS 72.92%
- Veröffentlicht 29.03.2013 16:09:05
- Zuletzt bearbeitet 11.04.2025 00:51:21
The web server in Novell ZENworks Configuration Management (ZCM) 10.3 and 11.2 before 11.2.4 does not properly perform authentication for zenworks/jsp/index.jsp, which allows remote attackers to conduct directory traversal attacks, and consequently u...
CVE-2013-1079
- EPSS 1.43%
- Veröffentlicht 29.03.2013 16:09:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
Directory traversal vulnerability in the ISCreateObject method in an ActiveX control in InstallShield\ISProxy.dll in AdminStudio in Novell ZENworks Configuration Management (ZCM) 10.3 through 11.2 allows remote attackers to execute arbitrary local DL...
CVE-2011-3174
- EPSS 20.27%
- Veröffentlicht 26.07.2012 22:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Buffer overflow in the DoFindReplace function in the ISGrid.Grid2.1 ActiveX control in InstallShield/ISGrid2.dll in AdminStudio in Novell ZENworks Configuration Management (ZCM) 10.2, 10.3, and 11 SP1 allows remote attackers to execute arbitrary code...
CVE-2011-2658
- EPSS 3.29%
- Veröffentlicht 26.07.2012 22:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
The ISList.ISAvi ActiveX control in AdminStudio in Novell ZENworks Configuration Management (ZCM) 10.2, 10.3, and 11 SP1 provides access to the mscomct2.ocx file, which allows remote attackers to execute arbitrary code by leveraging unspecified mscom...
CVE-2011-2657
- EPSS 74.4%
- Veröffentlicht 26.07.2012 22:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Directory traversal vulnerability in the LaunchProcess function in the LaunchHelp.HelpLauncher.1 ActiveX control in LaunchHelp.dll in AdminStudio in Novell ZENworks Configuration Management (ZCM) 10.2, 10.3, and 11 SP1 allows remote attackers to exec...