Show filters
61 Total Results
Displaying 31-40 of 61
Sort by:
Attacker Value
Unknown
CVE-2013-1080
Disclosure Date: March 29, 2013 (last updated October 05, 2023)
The web server in Novell ZENworks Configuration Management (ZCM) 10.3 and 11.2 before 11.2.4 does not properly perform authentication for zenworks/jsp/index.jsp, which allows remote attackers to conduct directory traversal attacks, and consequently upload and execute arbitrary programs, via a request to TCP port 443.
0
Attacker Value
Unknown
CVE-2013-1082
Disclosure Date: March 29, 2013 (last updated October 05, 2023)
Directory traversal vulnerability in DUSAP.php in Novell ZENworks Mobile Management before 2.7.1 allows remote attackers to include and execute arbitrary local files via the language parameter.
0
Attacker Value
Unknown
CVE-2013-1081
Disclosure Date: March 11, 2013 (last updated October 05, 2023)
Directory traversal vulnerability in MDM.php in Novell ZENworks Mobile Management (ZMM) 2.6.1 and 2.7.0 allows remote attackers to include and execute arbitrary local files via the language parameter.
0
Attacker Value
Unknown
CVE-2012-4933
Disclosure Date: October 20, 2012 (last updated October 05, 2023)
The rtrlet web application in the Web Console in Novell ZENworks Asset Management (ZAM) 7.5 uses a hard-coded username of Ivanhoe and a hard-coded password of Scott for the (1) GetFile_Password and (2) GetConfigInfo_Password operations, which allows remote attackers to obtain sensitive information via a crafted rtrlet/rtr request for the HandleMaintenanceCalls function.
0
Attacker Value
Unknown
CVE-2011-2658
Disclosure Date: July 26, 2012 (last updated October 04, 2023)
The ISList.ISAvi ActiveX control in AdminStudio in Novell ZENworks Configuration Management (ZCM) 10.2, 10.3, and 11 SP1 provides access to the mscomct2.ocx file, which allows remote attackers to execute arbitrary code by leveraging unspecified mscomct2 flaws.
0
Attacker Value
Unknown
CVE-2011-3174
Disclosure Date: July 26, 2012 (last updated October 04, 2023)
Buffer overflow in the DoFindReplace function in the ISGrid.Grid2.1 ActiveX control in InstallShield/ISGrid2.dll in AdminStudio in Novell ZENworks Configuration Management (ZCM) 10.2, 10.3, and 11 SP1 allows remote attackers to execute arbitrary code via a long bstrReplaceText parameter.
0
Attacker Value
Unknown
CVE-2011-2657
Disclosure Date: July 26, 2012 (last updated October 04, 2023)
Directory traversal vulnerability in the LaunchProcess function in the LaunchHelp.HelpLauncher.1 ActiveX control in LaunchHelp.dll in AdminStudio in Novell ZENworks Configuration Management (ZCM) 10.2, 10.3, and 11 SP1 allows remote attackers to execute arbitrary commands via a pathname in the first argument.
0
Attacker Value
Unknown
CVE-2012-2223
Disclosure Date: April 11, 2012 (last updated October 04, 2023)
The xplat agent in Novell ZENworks Configuration Management (ZCM) 10.3.x before 10.3.4 and 11.x before 11.2 enables the HTTP TRACE method, which might make it easier for remote attackers to conduct cross-site tracing (XST) attacks via unspecified vectors.
0
Attacker Value
Unknown
CVE-2012-2215
Disclosure Date: April 09, 2012 (last updated October 04, 2023)
Directory traversal vulnerability in the Preboot Service in Novell ZENworks Configuration Management (ZCM) 11.1 and 11.1a allows remote attackers to read arbitrary files via an opcode 0x21 request.
0
Attacker Value
Unknown
CVE-2011-3175
Disclosure Date: April 09, 2012 (last updated October 04, 2023)
Stack-based buffer overflow in the Preboot Service in Novell ZENworks Configuration Management (ZCM) 11.1 and 11.1a allows remote attackers to execute arbitrary code via an opcode 0x6c request.
0