CVE-2016-1593

HIGH

Micro Focus Novell Service Desk <7.2 - Path Traversal

Title source: llm

Description

Directory traversal vulnerability in the import users feature in Micro Focus Novell Service Desk before 7.2 allows remote authenticated administrators to upload and execute arbitrary JSP files via a .. (dot dot) in a filename within a multipart/form-data POST request to a LiveTime.woa URL.

Exploits (3)

exploitdb WORKING POC
by Metasploit · rubyremotemultiple
https://www.exploit-db.com/exploits/39708
exploitdb WRITEUP
by Pedro Ribeiro · textwebappsjsp
https://www.exploit-db.com/exploits/39687
metasploit WORKING POC EXCELLENT
rubypoclinux
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/novell_servicedesk_rce.rb

Scores

CVSS v3 7.2
EPSS 0.8511
EPSS Percentile 99.4%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-22
Status published
Products (1)
novell/service_desk < 7.1
Published Apr 22, 2016
Tracked Since Feb 18, 2026