CVE-2016-1593
published 2016-04-22CVE-2016-1593: Directory traversal vulnerability in the import users feature in Micro Focus Novell Service Desk before 7.2 allows remote authenticated administrators to…
PriorityP267high7.2CVSS 3.0
AVNACLPRHUINSUCHIHAH
EXPLOIT
EPSS
64.14%
99.1th percentile
Directory traversal vulnerability in the import users feature in Micro Focus Novell Service Desk before 7.2 allows remote authenticated administrators to upload and execute arbitrary JSP files via a .. (dot dot) in a filename within a multipart/form-data POST request to a LiveTime.woa URL.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| novell | service_desk | <= 7.1 | — |
Detection & IOCsextracted from sources · hover to see the quote
url/LiveTime/WebObjects/LiveTime.woa/wa/DownloadAction/downloadFile?attachmentId=1&entityName=ItemTypeAttach↗
- →Detect multipart/form-data POST requests to LiveTime.woa URLs containing directory traversal sequences (../) in the filename parameter of the Content-Disposition header, particularly targeting .jsp file uploads. ↗
- →Alert on POST requests to any URL matching the pattern /LiveTime/WebObjects/LiveTime.woa/wo/* with Content-Type multipart/form-data where the filename field contains '../' sequences. ↗
- →Monitor for GET requests to /LiveTime/WebObjects/LiveTime.woa/wa/DownloadAction/downloadLogFiles from non-administrative user sessions, indicating CVE-2016-1594 information disclosure exploitation. ↗
- →Detect newly created .jsp files under the Tomcat webapps/LiveTime/ directory, especially files with random alpha names (6–14 characters) consistent with Metasploit module payload naming. ↗
- →Flag HTTP requests using the specific User-Agent 'Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; Trident/6.0)' to LiveTime.woa endpoints, as this is the hardcoded UA in the Metasploit exploit module. ↗
- →Use the Google dork inurl:"LiveTime/WebObjects" to identify exposed Novell Service Desk instances for asset discovery and attack surface reduction. ↗
- →Monitor for execution of 'chmod 777' followed by a binary file drop in /tmp or similar world-writable directories on Linux hosts running Tomcat, consistent with the JSP payload execution chain. ↗
- ·Exploitation requires valid administrator credentials; the vulnerability is not unauthenticated. Detection should correlate file upload activity with authenticated admin sessions. ↗
- ·The traversal path to reach the Tomcat webapps directory differs between Linux VA (/srv/tomcat6/webapps/) and Windows installations; detections should account for both path variants. ↗
CVSS provenance
nvdv3.07.2HIGHCVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
Exploit-DB
Novell ServiceDesk - (Authenticated) Arbitrary File Upload (Metasploit)
exploitdb·2016-04-18
CVE-2016-1593 Novell ServiceDesk - (Authenticated) Arbitrary File Upload (Metasploit)
Novell ServiceDesk - (Authenticated) Arbitrary File Upload (Metasploit)
---
##
# This module requires Metasploit: http://metasploit.com/download
# Current source: https://github.com/rapid7/metasploit-framework
##
require 'msf/core'
class MetasploitModule 'Novell ServiceDesk Authenticated File Upload',
'Description' => %q{
This module exploits an authenticated arbitrary file upload via directory traversal
to execute code on the target. It has been tested on versions 6.5 and 7.1.0, in
Windows and Linux installations of Novell ServiceDesk, as well as the Virtual
Appliance provided by Novell.
},
'Author' =>
[
'Pedro Ribeiro ' # Vulnerability discovery and Metasploit module
],
'License' => MSF_LICENSE,
'References' =>
[
[ 'CVE', '2016-1593' ],
[ 'URL', 'https://raw.githubusercontent.com/ped
Exploit-DB
Novell ServiceDesk 6.5/7.0.3/7.1.0 - Multiple Vulnerabilities
exploitdb·2016-04-11·CVSS 7.2
CVE-2016-1596 [HIGH] Novell ServiceDesk 6.5/7.0.3/7.1.0 - Multiple Vulnerabilities
Novell ServiceDesk 6.5/7.0.3/7.1.0 - Multiple Vulnerabilities
---
>> Multiple vulnerabilities in Novell Service Desk 7.1.0, 7.0.3 and 6.5
>> Discovered by Pedro Ribeiro ([email protected]), Agile Information Security
Disclosure: 30/03/2016 / Last updated: 10/04/2016
>> Background on the affected products:
"Novell Service Desk 7.1.0 is a complete service management solution that allows you to easily monitor and solve services issues so that there is minimal disruption to your organization, which allows users to focus on the core business. Novell Service Desk provides an online support system to meet the service requirements of all your customers, administrators, supervisors, and technicians"
>> Summary:
Novell Service Desk has several vulnerabilities including a file upload function tha
Metasploit
Novell ServiceDesk Authenticated File Upload
metasploit
Novell ServiceDesk Authenticated File Upload
Novell ServiceDesk Authenticated File Upload
This module exploits an authenticated arbitrary file upload via directory traversal to execute code on the target. It has been tested on versions 6.5 and 7.1.0, in Windows and Linux installations of Novell ServiceDesk, as well as the Virtual Appliance provided by Novell.
No writeups or analysis indexed.
http://packetstormsecurity.com/files/136717/Novell-ServiceDesk-Authenticated-File-Upload.htmlhttp://www.rapid7.com/db/modules/exploit/multi/http/novell_servicedesk_rcehttp://www.securityfocus.com/archive/1/538043/100/0/threadedhttps://packetstormsecurity.com/files/136646https://raw.githubusercontent.com/pedrib/PoC/master/advisories/novell-service-desk-7.1.0.txthttps://www.exploit-db.com/exploits/39687/https://www.exploit-db.com/exploits/39708/https://www.novell.com/support/kb/doc.php?id=7017428http://packetstormsecurity.com/files/136717/Novell-ServiceDesk-Authenticated-File-Upload.htmlhttp://www.rapid7.com/db/modules/exploit/multi/http/novell_servicedesk_rcehttp://www.securityfocus.com/archive/1/538043/100/0/threadedhttps://packetstormsecurity.com/files/136646https://raw.githubusercontent.com/pedrib/PoC/master/advisories/novell-service-desk-7.1.0.txthttps://www.exploit-db.com/exploits/39687/https://www.exploit-db.com/exploits/39708/https://www.novell.com/support/kb/doc.php?id=7017428
2016-04-22
Published