Novell GroupWise Web Root Disclosure Vulnerability
BID:4206
Info
Novell GroupWise Web Root Disclosure Vulnerability
| Bugtraq ID: | 4206 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 28 2002 12:00AM |
| Updated: | Feb 28 2002 12:00AM |
| Credit: | Discovered by Tamer Sahin <[email protected]>. |
| Vulnerable: |
Novell Groupwise 5.5 |
| Not Vulnerable: | |
Discussion
Novell GroupWise Web Root Disclosure Vulnerability
Novell GroupWise is an email, calendaring and collaborative application available from Novell. It is designed for use on the Microsoft Windows and Novell Netware platforms, and includes a web access component for use through a web browser.
A vulnerability has been reported in some versions of GroupWise. Reportedly, if a maliciously formatted web request is submitted to the GWWEB.EXE cgi process, an error message will be returned. This error message will include the full path of the script.
Other versions of GroupWise may share this vulnerability. This has not, however, been confirmed.
Novell GroupWise is an email, calendaring and collaborative application available from Novell. It is designed for use on the Microsoft Windows and Novell Netware platforms, and includes a web access component for use through a web browser.
A vulnerability has been reported in some versions of GroupWise. Reportedly, if a maliciously formatted web request is submitted to the GWWEB.EXE cgi process, an error message will be returned. This error message will include the full path of the script.
Other versions of GroupWise may share this vulnerability. This has not, however, been confirmed.
Exploit / POC
Novell GroupWise Web Root Disclosure Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
Novell GroupWise Web Root Disclosure Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.