Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2016-1595
Description:LiveTime/WebObjects/LiveTime.woa/wa/DownloadAction/downloadFile in Micro Focus Novell Service Desk before 7.2 allows remote authenticated users to conduct Hibernate Query Language (HQL) injection attacks and obtain sensitive information via the entityName parameter.
Test IDs: None available
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2016-1595
Bugtraq: 20160410 [Multiple CVE]: RCE, info disclosure, HQL injection and stored XSS in Novell Service Desk 7.1.0 (Google Search)
http://www.securityfocus.com/archive/1/538043/100/0/threaded
https://www.exploit-db.com/exploits/39687/
https://packetstormsecurity.com/files/136646
https://raw.githubusercontent.com/pedrib/PoC/master/advisories/novell-service-desk-7.1.0.txt




© 1998-2025 E-Soft Inc. All rights reserved.