CVE-2014-0600
published 2014-08-29CVE-2014-0600: FileUploadServlet in the Administration service in Novell GroupWise 2014 before SP1 allows remote attackers to read or write to arbitrary files via the…
PriorityP341high7.8CVSS 2.0
AVNACLAuNCCINAN
EPSS
3.08%
86.2th percentile
FileUploadServlet in the Administration service in Novell GroupWise 2014 before SP1 allows remote attackers to read or write to arbitrary files via the poLibMaintenanceFileSave parameter, aka ZDI-CAN-2287.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| novell | groupwise | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.novell.com/support/kb/doc.php?id=7015566http://www.securitytracker.com/id/1030801http://www.zerodayinitiative.com/advisories/ZDI-14-296/https://bugzilla.novell.com/show_bug.cgi?id=879192http://www.novell.com/support/kb/doc.php?id=7015566http://www.securitytracker.com/id/1030801http://www.zerodayinitiative.com/advisories/ZDI-14-296/https://bugzilla.novell.com/show_bug.cgi?id=879192
2014-08-29
Published