PT-2002-1407 · Novell · Groupwise Webaccess

Publicado

2002-05-03

·

Atualizado

2016-10-18

·

CVE-2002-0341

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions GroupWise Web Access versions 5.5
Description The issue allows remote attackers to determine the full pathname of the web server via an HTTP request with an invalid HTMLVER parameter.
Recommendations For version 5.5, consider restricting access to the GWWEB.EXE until a patch is available. Avoid using the HTMLVER parameter in the affected HTTP request until the issue is resolved.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2002-0341

Produtos afetados

Groupwise Webaccess