Vulnerability record · CVE-2013-1081 · published 11 March 2013
CVE-2013-1081: Novell ZENworks Mobile Management directory traversal in MDM.php
Novell · Zenworks Mobile Management
MDM.php in Novell ZENworks Mobile Management 2.6.1 and 2.7.0 is vulnerable to directory traversal through the language parameter, allowing remote attackers to include and execute arbitrary local files. Because the flaw permits local file inclusion and execution, it can lead to code execution on the server and full compromise of the management platform.
Description
Directory traversal vulnerability in MDM.php in Novell ZENworks Mobile Management (ZMM) 2.6.1 and 2.7.0 allows remote attackers to include and execute arbitrary local files via the language parameter.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityUnauthenticated remote file inclusion and execution with a CVSS 2.0 score of 7.5 and very high EPSS probability make this a serious risk despite the absence of KEV listing.
What it is
MDM.php in Novell ZENworks Mobile Management 2.6.1 and 2.7.0 is vulnerable to directory traversal through the language parameter, allowing remote attackers to include and execute arbitrary local files. Because the flaw permits local file inclusion and execution, it can lead to code execution on the server and full compromise of the management platform.
Impact
An unauthenticated remote attacker can read and execute arbitrary local files on the ZENworks Mobile Management server, potentially leading to code execution and full system compromise.
Attack surface
Reachable over the network via HTTP requests to MDM.php with a crafted language parameter; the CVSS vector (AV:N/AC:L/Au:N) indicates no authentication and no user interaction are required.
Exploitation
Not listed in CISA KEV and no public exploit references are tagged, but EPSS is very high at 0.68 (99.3rd percentile), suggesting elevated likelihood of exploitation activity.
What to do
- Apply the vendor fix referenced in Novell support document 7011895; upgrade ZENworks Mobile Management beyond the affected 2.6.1 and 2.7.0 releases.
- Restrict network access to the ZENworks Mobile Management web interface to trusted management networks or VPN only.
- Validate and sanitize the language parameter server-side, rejecting path traversal sequences and restricting values to an allowlist.
- Run the ZENworks Mobile Management service with least privilege and monitor for unexpected file access or process execution.
Detection
- Inspect web server and application logs for requests to MDM.php containing traversal sequences such as ../ or encoded variants in the language parameter.
- Alert on unexpected local file reads or process spawns by the ZENworks Mobile Management service account.
- Monitor for anomalous outbound connections or new files in web-accessible directories following MDM.php requests.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2013-1081 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2013-1081), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.