CVE-2011-2750
published 2011-07-17CVE-2011-2750: NFRAgent.exe in Novell File Reporter 1.0.4.2 and earlier allows remote attackers to delete arbitrary files via a full pathname in an SRS OPERATION 4 CMD 5…
PriorityP343medium5CVSS 2.0
AVNACLAuNCNINAP
EXPLOIT
EPSS
16.68%
96.7th percentile
NFRAgent.exe in Novell File Reporter 1.0.4.2 and earlier allows remote attackers to delete arbitrary files via a full pathname in an SRS OPERATION 4 CMD 5 request to /FSF/CMD.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| novell | file_reporter | <= 1.0.4.2 | — |
| novell | file_reporter | — | — |
| novell | file_reporter | — | — |
| novell | file_reporter | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect HTTP requests targeting the /FSF/CMD endpoint on NFRAgent.exe with SRS payload containing OPERATION=4 and CMD=5, which triggers arbitrary file deletion ↗
- →Monitor for NFRAgent.exe process handling inbound network requests that result in unexpected file deletions, particularly on Windows platforms running NFR Agent 1.0.4.3 or 1.0.3.22 ↗
- ·Vulnerability affects Novell File Reporter 1.0.4.2 and earlier; verify version scope before applying detections ↗
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No writeups or analysis indexed.
http://aluigi.org/adv/nfr_2-adv.txthttp://secunia.com/advisories/45071http://securityreason.com/securityalert/8309http://securitytracker.com/id?1025716http://www.securityfocus.com/archive/1/518626/100/0/threadedhttp://aluigi.org/adv/nfr_2-adv.txthttp://secunia.com/advisories/45071http://securityreason.com/securityalert/8309http://securitytracker.com/id?1025716http://www.securityfocus.com/archive/1/518626/100/0/threaded
2011-07-17
Published