Novel ZENworks Mobile Management DUSAP.php language Param Code Execution

Strike ID:
E13-0v201
CVSS:
7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P)
False Positive:
f
Variants:
1
Year:
2013

Description

This strike exploits an arbitrary code execution vulnerability in Novel ZENworks Mobile Management. A crafted HEAD message to download.php can be sent to store arbitrary PHP code in a temporary file. A crafted POST message to DUSAP.php can then be sent to execute the code in the file.

CVE

Bid