CVE-2002-1437Path Traversal in Netware

3 documents3 sources
Severity
5.0MEDIUMNVD
EPSS
4.6%
top 10.74%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 11
Latest updateApr 30

Description

Directory traversal vulnerability in the web handler for Perl 5.003 on Novell NetWare 5.1 and NetWare 6 allows remote attackers to read arbitrary files via an HTTP request containing "..%5c" (URL-encoded dot-dot backslash) sequences.

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages1 packages

NVDnovell/netware5.1, 6.0+1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-pgf4-g67j-c3jw: Directory traversal vulnerability in the web handler for Perl 52022-04-30
CVEList
CVE-2002-1437: Directory traversal vulnerability in the web handler for Perl 52004-09-01
CVE-2002-1437 — Path Traversal in Novell Netware | cvebase