Description
NFRAgent.exe in Novell File Reporter 1.0.4.2 and earlier allows remote attackers to delete arbitrary files via a full pathname in an SRS OPERATION 4 CMD 5 request to /FSF/CMD.
Affected products
- Novell / file_reporter1.0.4.2
- Novell / file_reporter1.0.1 – 1.0.1
- Novell / file_reporter1.0.1.1 – 1.0.1.1
- Novell / file_reporter1.0.2 – 1.0.2