Vulnerabilities > CVE-2001-1458 - Unspecified vulnerability in Novell Groupwise 5.5/6.0
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Directory traversal vulnerability in Novell GroupWise 5.5 and 6.0 allows remote attackers to read arbitrary files via a request for /servlet/webacc?User.html= that contains "../" (dot dot) sequences and a null character.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 3 |
References
- http://online.securityfocus.com/archive/1/220667
- http://online.securityfocus.com/archive/1/220667
- http://support.novell.com/servlet/tidfinder/2960443
- http://support.novell.com/servlet/tidfinder/2960443
- http://www.foundstone.com/index.htm?subnav=resources/navigation.htm&subcontent=/resources/advisories_template.htm%3Findexid%3D12
- http://www.foundstone.com/index.htm?subnav=resources/navigation.htm&subcontent=/resources/advisories_template.htm%3Findexid%3D12
- http://www.kb.cert.org/vuls/id/341539
- http://www.kb.cert.org/vuls/id/341539
- http://www.novell.com/coolsolutions/gwmag/features/a_webaccess_security_gw.html
- http://www.novell.com/coolsolutions/gwmag/features/a_webaccess_security_gw.html
- http://www.securityfocus.com/bid/3436
- http://www.securityfocus.com/bid/3436
- https://exchange.xforce.ibmcloud.com/vulnerabilities/7287
- https://exchange.xforce.ibmcloud.com/vulnerabilities/7287