First published: Sun Dec 19 1999(Updated: )
Groupwise web server GWWEB.EXE allows remote attackers to read arbitrary files with .htm extensions via a .. (dot dot) attack using the HELP parameter.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Netscape Enterprise Server | =3.0.7a | |
Novell GroupWise | =5.5 | |
Novell GroupWise | =5.2 | |
=3.0.7a | ||
=5.2 | ||
=5.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-1999-1005 is considered to have a moderate severity level due to the potential for unauthorized file access.
To fix CVE-1999-1005, you should patch the affected version of the GroupWise web server or implement access controls to prevent directory traversal attacks.
CVE-1999-1005 affects Netscape Enterprise Server version 3.0.7a and Novell GroupWise versions 5.2 and 5.5.
Yes, CVE-1999-1005 can be exploited remotely by attackers to read arbitrary files on the server.
A '..' (dot dot) attack refers to a directory traversal attack that allows attackers to navigate to parent directories to access restricted files.