Nombas ScriptEase:Webserver Edition Default Script Vulnerability

BID:3715

Info

Nombas ScriptEase:Webserver Edition Default Script Vulnerability

Bugtraq ID: 3715
Class: Input Validation Error
CVE:
Remote: Yes
Local: No
Published: Dec 19 2001 12:00AM
Updated: Dec 19 2001 12:00AM
Credit: Discovered by Martyn Ruks ([email protected]) and posted in an IRM Security Advisory on December 19, 2001.
Vulnerable: Nombas ScriptEase: Webserver Edition 4.30 d win3.x
Nombas ScriptEase: Webserver Edition 4.30 d OS/2
Nombas ScriptEase: Webserver Edition 4.30 d Netware 5
+ Novell Netware 5.1
Nombas ScriptEase: Webserver Edition 4.30 d ISAPI win32
Nombas ScriptEase: Webserver Edition 4.30 d CGI/WINCGI win32
Nombas ScriptEase: Webserver Edition 4.30 b solaris
Nombas ScriptEase: Webserver Edition 4.30 b ppc
Nombas ScriptEase: Webserver Edition 4.30 b Linux
Nombas ScriptEase: Webserver Edition 4.30 b Irix
Nombas ScriptEase: Webserver Edition 4.30 b HP-UX
Nombas ScriptEase: Webserver Edition 4.30 b FreeBSD
Not Vulnerable:

Discussion

Nombas ScriptEase:Webserver Edition Default Script Vulnerability

Nombas ScriptEase:Webserver Edition is designed to allow the development of web based applications in Javascript. It includes the ability to execute Javascript code in response to CGI requests, and support for developer features such as remote debugging.

Default scripts included with ScriptEase:Webserver Edition allows remote users to disclose arbitrary files residing on a host. The file to view is passed as a parameter in a specially crafted URL. Additionally, ../ directory traversal allows an attacker to view any file on the web server.

Currently 'viewcode.jse' and 'comment2.jse' have been known to exploit this issue.

Exploit / POC

Nombas ScriptEase:Webserver Edition Default Script Vulnerability

This vulnerability can be exploited with a web browser.

Solution / Fix

Nombas ScriptEase:Webserver Edition Default Script Vulnerability

Solution:
Delete the example scripts viewcode.jse and comment2.jse. Reportedly, users with NetWare 5.1 SP3 are not affected by this issue.


Nombas ScriptEase: Webserver Edition 4.30 d Netware 5

References

Nombas ScriptEase:Webserver Edition Default Script Vulnerability

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report