PT-2004-2999 · Novell · Novell Netware Enterprise Web Server
Published
2004-12-31
·
Updated
2018-10-30
·
CVE-2004-2103
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Novell NetWare Enterprise Web Server versions 5.1 through 6.0
Description
A cross-site scripting issue allows remote attackers to execute arbitrary script or HTML as other users. This can be achieved through various means, including a malformed request for a Perl program with script in the filename, the
User.id parameter to the webacc servlet, the GWAP.version parameter to webacc, or a URL request for a .bas file with script in the filename.Recommendations
For Novell NetWare Enterprise Web Server versions 5.1 through 6.0, consider disabling the webacc servlet and restricting access to .bas and Perl files until a patch is available. Avoid using the
User.id and GWAP.version parameters in the webacc servlet to minimize the risk of exploitation.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Novell Netware Enterprise Web Server