5
CVSSv2

CVE-1999-0175

Published: 01/07/1996 Updated: 17/08/2022
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

The convert.bas program in the Novell web server allows a remote malicious users to read any file on the system that is internally accessible by the web server.

Vulnerable Product Search on Vulmon Subscribe to Product

novell web server 1.0

Exploits

source: wwwsecurityfocuscom/bid/2025/info Novell NetWare Web Server 2x versions came with a CGI written in BASIC called convertbas This script allows retrieval of files outside of the normal web server context This can be accomplished simply by submitting the filename and path as a parameter to the script, using relative paths (// ...