cve,link,title,description,vendor,products,score,severity,epss,cisa,article,ransomware,exploited,poc,trended,trended_no_1,published,trended_score CVE-2016-1593,https://securityvulnerability.io/vulnerability/CVE-2016-1593,,Directory traversal vulnerability in the import users feature in Micro Focus Novell Service Desk before 7.2 allows remote authenticated administrators to upload and execute arbitrary JSP files via a .. (dot dot) in a filename within a multipart/form-data POST request to a LiveTime.woa URL.,Novell,Service Desk,7.2,HIGH,0.8389599919319153,false,false,false,false,,false,false,2016-04-22T10:00:00.000Z,0 CVE-2016-1594,https://securityvulnerability.io/vulnerability/CVE-2016-1594,,"Micro Focus Novell Service Desk before 7.2 allows remote authenticated users to read arbitrary attachments via a request to a LiveTime.woa URL, as demonstrated by obtaining sensitive information via a (1) downloadLogFiles or (2) downloadFile action.",Novell,Service Desk,6.5,MEDIUM,0.06300000101327896,false,false,false,false,,false,false,2016-04-22T10:00:00.000Z,0 CVE-2016-1595,https://securityvulnerability.io/vulnerability/CVE-2016-1595,,LiveTime/WebObjects/LiveTime.woa/wa/DownloadAction/downloadFile in Micro Focus Novell Service Desk before 7.2 allows remote authenticated users to conduct Hibernate Query Language (HQL) injection attacks and obtain sensitive information via the entityName parameter.,Novell,Service Desk,6.5,MEDIUM,0.00419999985024333,false,false,false,false,,false,false,2016-04-22T10:00:00.000Z,0 CVE-2016-1596,https://securityvulnerability.io/vulnerability/CVE-2016-1596,,"Multiple cross-site scripting (XSS) vulnerabilities in Micro Focus Novell Service Desk before 7.2 allow remote authenticated users to inject arbitrary web script or HTML via a certain (1) user name, (2) tf_aClientFirstName, (3) tf_aClientLastName, (4) ta_selectedTopicContent, (5) tf_orgUnitName, (6) tf_aManufacturerFullName, (7) tf_aManufacturerName, (8) tf_aManufacturerAddress, or (9) tf_aManufacturerCity parameter.",Novell,Service Desk,5.4,MEDIUM,0.01217000000178814,false,false,false,false,,false,false,2016-04-22T10:00:00.000Z,0