First published: Fri Apr 11 2003(Updated: )
Directory traversal vulnerability in Novell NetBasic Scripting Server (NSN) for Netware 5.1 and 6, and Novell Small Business Suite 5.1 and 6, allows remote attackers to read arbitrary files via a URL containing a "..%5c" sequence (modified dot-dot), which is mapped to the directory separator.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Novell Small Business Suite | =5.1 | |
Novell Small Business Suite | =6.0 | |
Novell NetWare FTP Server | =5.1 | |
Novell NetWare FTP Server | =6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-1417 has a medium severity rating due to its potential to allow remote attackers to access sensitive files.
To fix CVE-2002-1417, ensure that your Novell Small Business Suite and NetWare servers are updated to the latest patches provided by Novell.
CVE-2002-1417 affects Novell NetWare versions 5.1 and 6.0, as well as Novell Small Business Suite versions 5.1 and 6.0.
CVE-2002-1417 is a directory traversal vulnerability that allows attackers to manipulate URLs to access restricted files.
Exploitation of CVE-2002-1417 is relatively easy, requiring only a crafted URL with specific traversal sequences.