5
CVSSv2

CVE-1999-1005

Published: 19/12/1999 Updated: 18/10/2016
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Groupwise web server GWWEB.EXE allows remote malicious users to read arbitrary files with .htm extensions via a .. (dot dot) attack using the HELP parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

novell groupwise 5.5

netscape enterprise server 3.0.7a

novell groupwise 5.2

Exploits

Netscape Enterprise Server for NetWare 4/5 307 a,Novell Groupwise 52/55 GWWEBEXE Multiple Vulnerabilities source: wwwsecurityfocuscom/bid/879/info The HELP function in GWWEBEXE will reveal the path of the server, and combined with the '/' string, allow read access for any client to any htm file on the server, as well as browseab ...