Vulnerabilities > CVE-2002-1437 - Directory Traversal vulnerability in Novell Netware 5.1/6.0

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
novell
nessus

Summary

Directory traversal vulnerability in the web handler for Perl 5.003 on Novell NetWare 5.1 and NetWare 6 allows remote attackers to read arbitrary files via an HTTP request containing "..%5c" (URL-encoded dot-dot backslash) sequences.

Vulnerable Configurations

Part Description Count
OS
Novell
4

Nessus

NASL familyNetware
NASL idNETWARE_POST_PERL.NASL
descriptionNovell NetWare contains multiple default web server installations. The NetWare Enterprise Web Server (Netscape/IPlanet) has a perl handler that will run arbitrary code given in a POST request. Versions 5.x (through SP4) and 6.x (through SP1) are affected.
last seen2020-06-01
modified2020-06-02
plugin id11158
published2002-11-21
reporterThis script is Copyright (C) 2002-2018 visigoth
sourcehttps://www.tenable.com/plugins/nessus/11158
titleNovell NetWare Web Handler Multiple Vulnerabilities