CVE-2004-2104
published 2004-12-31CVE-2004-2104: Novell NetWare Enterprise Web Server 5.1 and 6.0 allows remote attackers to obtain sensitive server information, including the internal IP address, via a…
PriorityP430medium5CVSS 2.0
AVNACLAuNCPINAN
EXPLOIT
EPSS
11.94%
95.7th percentile
Novell NetWare Enterprise Web Server 5.1 and 6.0 allows remote attackers to obtain sensitive server information, including the internal IP address, via a direct request to (1) snoop.jsp, (2) SnoopServlet, (3) env.bas, or (4) lcgitest.nlm.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| novell | netware | — | — |
| novell | netware | — | — |
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
Exploit-DB
Novell Netware Enterprise Web Server 5.1/6.0 SnoopServlet - Information Disclosure
exploitdb·2004-01-23
CVE-2004-2104 Novell Netware Enterprise Web Server 5.1/6.0 SnoopServlet - Information Disclosure
Novell Netware Enterprise Web Server 5.1/6.0 SnoopServlet - Information Disclosure
---
source: https://www.securityfocus.com/bid/9479/info
Multiple vulnerabilities have been identified in Novell Netware Enterprise Web Server that may allow an attacker to carry out cross-site scripting attacks, disclose sensitive information, and load potentially malicious files on a vulnerable server.
http://www.example.com/servlet/SnoopServlet
Exploit-DB
Novell Netware Enterprise Web Server 5.1/6.0 - env.bas Information Disclosure
exploitdb·2004-01-23
CVE-2004-2104 Novell Netware Enterprise Web Server 5.1/6.0 - env.bas Information Disclosure
Novell Netware Enterprise Web Server 5.1/6.0 - env.bas Information Disclosure
---
source: https://www.securityfocus.com/bid/9479/info
Multiple vulnerabilities have been identified in Novell Netware Enterprise Web Server that may allow an attacker to carry out cross-site scripting attacks, disclose sensitive information, and load potentially malicious files on a vulnerable server.
http://www.example.com/nsn/"msgbox%20sadas".bas
Exploit-DB
Novell Netware Enterprise Web Server 5.1/6.0 - snoop.jsp Information Disclosure
exploitdb·2004-01-23
CVE-2004-2104 Novell Netware Enterprise Web Server 5.1/6.0 - snoop.jsp Information Disclosure
Novell Netware Enterprise Web Server 5.1/6.0 - snoop.jsp Information Disclosure
---
source: https://www.securityfocus.com/bid/9479/info
Multiple vulnerabilities have been identified in Novell Netware Enterprise Web Server that may allow an attacker to carry out cross-site scripting attacks, disclose sensitive information, and load potentially malicious files on a vulnerable server.
http://www.example.com/examples/jsp/snp/snoop.jsp
No writeups or analysis indexed.
http://marc.info/?l=bugtraq&m=107487862304440&w=2http://secunia.com/advisories/10711http://www.osvdb.org/3715http://www.osvdb.org/3720http://www.osvdb.org/3721http://www.osvdb.org/3722http://www.osvdb.org/4952http://www.securityfocus.com/bid/9479https://exchange.xforce.ibmcloud.com/vulnerabilities/14921http://marc.info/?l=bugtraq&m=107487862304440&w=2http://secunia.com/advisories/10711http://www.osvdb.org/3715http://www.osvdb.org/3720http://www.osvdb.org/3721http://www.osvdb.org/3722http://www.osvdb.org/4952http://www.securityfocus.com/bid/9479https://exchange.xforce.ibmcloud.com/vulnerabilities/14921
2004-12-31
Published