First published: Fri Apr 11 2003(Updated: )
Directory traversal vulnerability in the web handler for Perl 5.003 on Novell NetWare 5.1 and NetWare 6 allows remote attackers to read arbitrary files via an HTTP request containing "..%5c" (URL-encoded dot-dot backslash) sequences.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Novell NetWare | =5.1 | |
Novell NetWare | =5.1-sp4 | |
Novell NetWare | =6.0-sp1 | |
Novell NetWare | =6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-1437 is considered to have a medium severity level due to its potential for unauthorized access to sensitive files.
To fix CVE-2002-1437, it is recommended to upgrade to a newer version of Novell NetWare that addresses this vulnerability.
CVE-2002-1437 affects Novell NetWare 5.1, specifically SP4, and Novell NetWare 6.0, specifically SP1 and the base version.
Yes, CVE-2002-1437 can be exploited remotely by attackers sending specially crafted HTTP requests.
CVE-2002-1437 is a directory traversal vulnerability, allowing attackers to read arbitrary files outside of the intended directory.