{"api_version":"1","generated_at":"2026-07-24T19:34:53+00:00","cve":"CVE-2008-2432","urls":{"html":"https://cve.report/CVE-2008-2432","api":"https://cve.report/api/cve/CVE-2008-2432.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2008-2432","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2008-2432"},"summary":{"title":"CVE-2008-2432","description":"Insecure method vulnerability in the GetFileList method in an unspecified ActiveX control in Novell iPrint Client before 5.06 allows remote attackers to list the image files in an arbitrary directory via a directory name in the argument.","state":"PUBLISHED","assigner":"flexera","published_at":"2008-11-26 01:30:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-200","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.securityfocus.com/bid/30813","name":"http://www.securityfocus.com/bid/30813","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Novell iPrint Client ActiveX Control Multiple Remote Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://secunia.com/secunia_research/2008-30/advisory/","name":"http://secunia.com/secunia_research/2008-30/advisory/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"About Secunia Research | Flexera","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/30667","name":"http://secunia.com/advisories/30667","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Novell iPrint Client ActiveX Control Multiple Vulnerabilities - Secunia Advisories - Vulnerability Intelligence - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2008-2432","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2008-2432","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2008","cve_id":"2432","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"novell","cpe5":"iprint","cpe6":"4.26","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"2432","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"novell","cpe5":"iprint","cpe6":"4.27","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"2432","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"novell","cpe5":"iprint","cpe6":"4.28","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"2432","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"novell","cpe5":"iprint","cpe6":"4.30","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"2432","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"novell","cpe5":"iprint","cpe6":"4.32","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"2432","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"novell","cpe5":"iprint","cpe6":"4.34","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"2432","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"novell","cpe5":"iprint","cpe6":"4.36","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"2432","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"novell","cpe5":"iprint","cpe6":"4.38","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"2432","vulnerable":"1","versionEndIncluding":"5.04","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"novell","cpe5":"iprint","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T08:58:02.683Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"30667","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/30667"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://secunia.com/secunia_research/2008-30/advisory/"},{"name":"30813","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/30813"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"descriptions":[{"lang":"en","value":"Insecure method vulnerability in the GetFileList method in an unspecified ActiveX control in Novell iPrint Client before 5.06 allows remote attackers to list the image files in an arbitrary directory via a directory name in the argument."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2008-11-26T01:00:00.000Z","orgId":"44d08088-2bea-4760-83a6-1e9be26b15ab","shortName":"flexera"},"references":[{"name":"30667","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/30667"},{"tags":["x_refsource_MISC"],"url":"http://secunia.com/secunia_research/2008-30/advisory/"},{"name":"30813","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/30813"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"PSIRT-CNA@flexerasoftware.com","ID":"CVE-2008-2432","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Insecure method vulnerability in the GetFileList method in an unspecified ActiveX control in Novell iPrint Client before 5.06 allows remote attackers to list the image files in an arbitrary directory via a directory name in the argument."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"30667","refsource":"SECUNIA","url":"http://secunia.com/advisories/30667"},{"name":"http://secunia.com/secunia_research/2008-30/advisory/","refsource":"MISC","url":"http://secunia.com/secunia_research/2008-30/advisory/"},{"name":"30813","refsource":"BID","url":"http://www.securityfocus.com/bid/30813"}]}}}},"cveMetadata":{"assignerOrgId":"44d08088-2bea-4760-83a6-1e9be26b15ab","assignerShortName":"flexera","cveId":"CVE-2008-2432","datePublished":"2008-11-26T01:00:00.000Z","dateReserved":"2008-05-27T00:00:00.000Z","dateUpdated":"2024-09-17T02:01:41.375Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2008-11-26 01:30:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-200","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:novell:iprint:*:*:*:*:*:*:*:*","versionEndIncluding":"5.04","matchCriteriaId":"A5538B39-4C1E-42AE-9B93-6203C77A9C91"},{"vulnerable":true,"criteria":"cpe:2.3:a:novell:iprint:4.26:*:*:*:*:*:*:*","matchCriteriaId":"3332CB43-D2ED-4720-8ED4-AE222C6F7FF3"},{"vulnerable":true,"criteria":"cpe:2.3:a:novell:iprint:4.27:*:*:*:*:*:*:*","matchCriteriaId":"E9AD9057-2218-481E-96CB-BF568AD3A9F2"},{"vulnerable":true,"criteria":"cpe:2.3:a:novell:iprint:4.28:*:*:*:*:*:*:*","matchCriteriaId":"0D044326-00CB-4158-A652-7D7FBDB380C7"},{"vulnerable":true,"criteria":"cpe:2.3:a:novell:iprint:4.30:*:*:*:*:*:*:*","matchCriteriaId":"3BDA0CD3-3E49-42E9-8D41-2B93FEE53610"},{"vulnerable":true,"criteria":"cpe:2.3:a:novell:iprint:4.32:*:*:*:*:*:*:*","matchCriteriaId":"AAB01661-76E1-4181-A798-6325EFD681FE"},{"vulnerable":true,"criteria":"cpe:2.3:a:novell:iprint:4.34:*:*:*:*:*:*:*","matchCriteriaId":"16769BC0-66AE-4AA3-B504-03389717A56D"},{"vulnerable":true,"criteria":"cpe:2.3:a:novell:iprint:4.36:*:*:*:*:*:*:*","matchCriteriaId":"25B2994C-8E01-4E7B-A5CA-9F9BE4C634C7"},{"vulnerable":true,"criteria":"cpe:2.3:a:novell:iprint:4.38:*:*:*:*:*:*:*","matchCriteriaId":"CCCA90D8-A320-43B0-A667-DAFC0D00924F"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2008","CveId":"2432","Ordinal":"1","Title":"CVE-2008-2432","CVE":"CVE-2008-2432","Year":"2008"},"notes":[{"CveYear":"2008","CveId":"2432","Ordinal":"1","NoteData":"Insecure method vulnerability in the GetFileList method in an unspecified ActiveX control in Novell iPrint Client before 5.06 allows remote attackers to list the image files in an arbitrary directory via a directory name in the argument.","Type":"Description","Title":"CVE-2008-2432"},{"CveYear":"2008","CveId":"2432","Ordinal":"2","NoteData":"2008-11-25","Type":"Other","Title":"Published"}]}}}