First published: Fri May 03 2002(Updated: )
GWWEB.EXE in GroupWise Web Access 5.5, and possibly other versions, allows remote attackers to determine the full pathname of the web server via an HTTP request with an invalid HTMLVER parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Micro Focus GroupWise | =5.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-0341 is considered to have a low severity as it primarily allows information disclosure.
To fix CVE-2002-0341, it is recommended to upgrade to a patched version of GroupWise Web Access beyond 5.5.
CVE-2002-0341 affects GroupWise Web Access version 5.5 and potentially other versions.
While CVE-2002-0341 primarily discloses the web server's pathname, it could potentially assist in further attacks if exploited.
CVE-2002-0341 allows attackers to gather information that may be used for reconnaissance before launching targeted attacks.