Blog

Wednesday 6 October 2010 - Novell iManager Arbitrary File Upload Remote Code Execution Vulnerability

TippingPoint's Zero Day Initiative (ZDI) have published an advisory for a remote pre authentication arbitrary file upload vulnerability in Novell iManager that leads to arbitrary code execution. This vulnerability was discovered by Stephen Fewer of Harmony Security.

You can read the full ZDI advisory here:
http://www.zerodayinitiative.com/advisories/ZDI-10-190/

And the Novell advisory here:
http://www.novell.com/support/viewContent.do?externalId=7006515&sliceId=2

Labels:

 

0 Comments:

Post a Comment