cbcvebase.
CVE-2011-2750
published 2011-07-17

CVE-2011-2750: NFRAgent.exe in Novell File Reporter 1.0.4.2 and earlier allows remote attackers to delete arbitrary files via a full pathname in an SRS OPERATION 4 CMD 5…

PriorityP343medium5CVSS 2.0
AVNACLAuNCNINAP
EXPLOIT
EPSS
16.68%
96.7th percentile
NFRAgent.exe in Novell File Reporter 1.0.4.2 and earlier allows remote attackers to delete arbitrary files via a full pathname in an SRS OPERATION 4 CMD 5 request to /FSF/CMD.

Affected

4 ranges
VendorProductVersion rangeFixed in
novellfile_reporter<= 1.0.4.2
novellfile_reporter
novellfile_reporter
novellfile_reporter

Detection & IOCsextracted from sources · hover to see the quote

path/FSF/CMD
processNFRAgent.exe
commandSRS OPERATION=4 CMD=5
  • Detect HTTP requests targeting the /FSF/CMD endpoint on NFRAgent.exe with SRS payload containing OPERATION=4 and CMD=5, which triggers arbitrary file deletion
  • Monitor for NFRAgent.exe process handling inbound network requests that result in unexpected file deletions, particularly on Windows platforms running NFR Agent 1.0.4.3 or 1.0.3.22
  • ·Vulnerability affects Novell File Reporter 1.0.4.2 and earlier; verify version scope before applying detections
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.