Description
Groupwise web server GWWEB.EXE allows remote attackers to read arbitrary files with .htm extensions via a .. (dot dot) attack using the HELP parameter.
Affected products
- netscape / enterprise_server3.0.7a – 3.0.7a
- Novell / groupwise5.2 – 5.2
- Novell / groupwise5.5 – 5.5
Exploits & proofs of concept
- exploit-dbNetscape Enterprise Server / Novell Groupwise 5.2/5.5 - 'GWWEB.EXE' Multiple Vulnerabilitiesby Sacha Faust Bourque
References
Updated 10m ago · 8 sources