| Vulnerability Name: | CVE-2001-1232 (CCN-6988) | ||||||||
| Assigned: | 2001-08-14 | ||||||||
| Published: | 2001-08-14 | ||||||||
| Updated: | 2017-12-19 | ||||||||
| Summary: | GroupWise WebAccess 5.5 with directory indexing enabled allows a remote attacker to view arbitrary directory contents via an HTTP request with a lowercase "get". | ||||||||
| CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
| CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
| ||||||||
| Vulnerability Type: | CWE-Other | ||||||||
| Vulnerability Consequences: | Obtain Information | ||||||||
| References: | Source: MITRE Type: CNA CVE-2001-1232 Source: CCN Type: Nomad Mobile Research Centre Advisory 14Aug2001 Various - NetWare Enterprise Web Server and GroupWise WebAccess Source: CCN Type: OSVDB ID: 3488 Novell NetWare Malformed GET Directory Listing Source: BUGTRAQ Type: Exploit, Patch, Vendor Advisory 20010815 Groupwise Webaccess, NetWare web server, and Novell Source: BID Type: UNKNOWN 3188 Source: CCN Type: BID-3188 Novell Groupwise Directory Disclosure Vulnerability Source: XF Type: UNKNOWN netware-get-directory-listing(6988) Source: XF Type: UNKNOWN netware-get-directory-listing(6988) | ||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
| BACK | |||||||||