Directory traversal vulnerability in the getEntry method in the PortalModuleInstallManager component in a servlet in nps.jar in the Administration Console (aka Access Management Console) in Novell Access Manager 3.1 before 3.1.2-281 on Windows allows remote attackers to create arbitrary files with any contents, and consequently execute arbitrary code, via a .. (dot dot) in a parameter, aka ZDI-CAN-678.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2010-06-18T16:00:00

Updated: 2024-08-07T00:45:11.744Z

Reserved: 2010-01-12T00:00:00

Link: CVE-2010-0284

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2010-06-18T16:30:01.313

Modified: 2017-08-17T01:31:57.053

Link: CVE-2010-0284

cve-icon Redhat

No data.