7.5
CVSSv2

CVE-1999-1020

Published: 18/09/1998 Updated: 19/12/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The installation of Novell Netware NDS 5.99 provides an unauthenticated client with Read access for the tree, which allows remote malicious users to access sensitive information such as users, groups, and readable objects via CX.EXE and NLIST.EXE.

Vulnerable Product Search on Vulmon Subscribe to Product

novell netware 4.1

novell netware 4.11

Exploits

source: wwwsecurityfocuscom/bid/484/info Non-authenticated clients have access to CXEXE and NLISTEXE in the SYS:LOGIN directory of a Netware 4x server The default root access is set to Read Therefore, by using various switch options in CXEXE and NLISTEXE, anyone connecting to the server can gain access to NDS tree information such ...