CVE-2016-1595
23Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 6.6%
from disclosure to weapon0 days
Published on NVDApr 22
1st PoCApr 11
exploitation probability
6.6%top 7% of all CVEs
observed exploitation
nono source reports it
3 public exploit(s)
LiveTime/WebObjects/LiveTime.woa/wa/DownloadAction/downloadFile in Micro Focus Novell Service Desk before 7.2 allows remote authenticated users to conduct Hibernate Query Language (HQL) injection attacks and obtain sensitive information via the entityName parameter.
Affected products
n/a · n/apublic PoCs found — 3
exploitdbwww.exploit-db.com/exploits/39687unverifiedcve_referencepacketstormsecurity.com/files/136646unverifiedcve_referencewww.exploit-db.com/exploits/39687/unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
https://packetstormsecurity.com/files/136646https://raw.githubusercontent.com/pedrib/PoC/master/advisories/novell-service-desk-7.1.0.txthttps://www.exploit-db.com/exploits/39687/https://www.novell.com/support/kb/doc.php?id=7017430http://www.securityfocus.com/archive/1/538043/100/0/threaded