RULE(RULE ID:336719)

Rule General Information
Release Date: 2022-06-29
Rule Name: Novell File Reporter FSFUI File Upload Vulnerability (CVE-2012-4959)
Severity:
CVE ID:
Rule Protection Details
Description: Directory traversal vulnerability in NFRAgent.exe in Novell File Reporter 1.0.2 allows remote attackers to upload and execute files via a 130 /FSF/CMD request with a .. (dot dot) in a FILE element of an FSFUI record.
Impact: An attacker could exploit this vulnerability to have unspecified effect.
Affected OS: Windows, Linux, Others
Reference: http://www.kb.cert.org/vuls/id/273371
https://community.rapid7.com/community/metasploit/blog/2012/11/16/nfr-agent-buffer-vulnerabilites-cve-2012-4959
Solutions
The vendor has released upgrade patches to fix vulnerabilities, please visit:
http://www.kb.cert.org/vuls/id/273371