Vulnerability Details CVE-2013-1093
Open redirect vulnerability in the fwdToURL function in the ZCC login page in zcc-framework.jar in Novell ZENworks Configuration Management (ZCM) 11.2 before 11.2.3a Monthly Update 1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the directToPage parameter.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.02
EPSS Ranking 83.1%
CVSS Severity
CVSS v2 Score 5.8
Products affected by CVE-2013-1093
-
cpe:2.3:a:novell:zenworks_configuration_management:11.2
-
cpe:2.3:a:novell:zenworks_configuration_management:11.2.1
-
cpe:2.3:a:novell:zenworks_configuration_management:11.2.2
-
cpe:2.3:a:novell:zenworks_configuration_management:11.2.3