GWWEB.EXE in GroupWise Web Access 5.5, and possibly other versions, allows remote malicious users to determine the full pathname of the web server via an HTTP request with an invalid HTMLVER parameter.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
novell groupwise 5.5 |