Lucene search

K
cveMitreCVE-2013-1079
HistoryMar 29, 2013 - 4:09 p.m.

CVE-2013-1079

2013-03-2916:09:04
CWE-22
mitre
web.nvd.nist.gov
26
cve-2013-1079
directory traversal
iscreateobject
activex control
installshield
novell zenworks configuration management
zcm
remote code execution

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

7.4

Confidence

High

EPSS

0.023

Percentile

89.9%

Directory traversal vulnerability in the ISCreateObject method in an ActiveX control in InstallShield\ISProxy.dll in AdminStudio in Novell ZENworks Configuration Management (ZCM) 10.3 through 11.2 allows remote attackers to execute arbitrary local DLL files via a crafted web page that also calls the Initialize method.

Affected configurations

Nvd
Node
novellzenworks_configuration_managementMatch10.3
OR
novellzenworks_configuration_managementMatch10.3.1
OR
novellzenworks_configuration_managementMatch10.3.2
OR
novellzenworks_configuration_managementMatch10.3.3
OR
novellzenworks_configuration_managementMatch11
OR
novellzenworks_configuration_managementMatch11.1
OR
novellzenworks_configuration_managementMatch11.1a
OR
novellzenworks_configuration_managementMatch11.2
VendorProductVersionCPE
novellzenworks_configuration_management10.3cpe:2.3:a:novell:zenworks_configuration_management:10.3:*:*:*:*:*:*:*
novellzenworks_configuration_management10.3.1cpe:2.3:a:novell:zenworks_configuration_management:10.3.1:*:*:*:*:*:*:*
novellzenworks_configuration_management10.3.2cpe:2.3:a:novell:zenworks_configuration_management:10.3.2:*:*:*:*:*:*:*
novellzenworks_configuration_management10.3.3cpe:2.3:a:novell:zenworks_configuration_management:10.3.3:*:*:*:*:*:*:*
novellzenworks_configuration_management11cpe:2.3:a:novell:zenworks_configuration_management:11:*:*:*:*:*:*:*
novellzenworks_configuration_management11.1cpe:2.3:a:novell:zenworks_configuration_management:11.1:*:*:*:*:*:*:*
novellzenworks_configuration_management11.1acpe:2.3:a:novell:zenworks_configuration_management:11.1a:*:*:*:*:*:*:*
novellzenworks_configuration_management11.2cpe:2.3:a:novell:zenworks_configuration_management:11.2:*:*:*:*:*:*:*

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

7.4

Confidence

High

EPSS

0.023

Percentile

89.9%

Related for CVE-2013-1079