Novell NetWare ApacheAdmin Security Bypass Vulnerability
BID:32657
Info
Novell NetWare ApacheAdmin Security Bypass Vulnerability
| Bugtraq ID: | 32657 |
| Class: | Unknown |
| CVE: |
CVE-2008-5696 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 05 2008 12:00AM |
| Updated: | Dec 29 2008 04:42PM |
| Credit: | Reported by the vendor |
| Vulnerable: |
Novell Netware 6.5 SP7 Novell Netware 6.5 SP6 Novell Netware 6.5 SP5 Novell Apache 2.0.48 |
| Not Vulnerable: |
Novell Netware 6.5.0 SP8 |
Discussion
Novell NetWare ApacheAdmin Security Bypass Vulnerability
Novell NetWare is prone to a security-bypass vulnerability.
Attackers can exploit this issue to gain unauthorized access to the ApacheAdmin console. Successfully exploiting this issue will lead to further attacks.
Novell NetWare is prone to a security-bypass vulnerability.
Attackers can exploit this issue to gain unauthorized access to the ApacheAdmin console. Successfully exploiting this issue will lead to further attacks.
Exploit / POC
Novell NetWare ApacheAdmin Security Bypass Vulnerability
No specific exploit is required. An attacker would only need remote access to Novell Netware.
No specific exploit is required. An attacker would only need remote access to Novell Netware.
Solution / Fix
Novell NetWare ApacheAdmin Security Bypass Vulnerability
Solution:
The vendor released an update to address this issue. Please see the references for more information.
Solution:
The vendor released an update to address this issue. Please see the references for more information.
References
Novell NetWare ApacheAdmin Security Bypass Vulnerability
References:
References: