Vulnerability Name: | CVE-2008-2432 (CCN-44615) | ||||||||
Assigned: | 2008-08-25 | ||||||||
Published: | 2008-08-25 | ||||||||
Updated: | 2008-11-26 | ||||||||
Summary: | Insecure method vulnerability in the GetFileList method in an unspecified ActiveX control in Novell iPrint Client before 5.06 allows remote attackers to list the image files in an arbitrary directory via a directory name in the argument. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N) 3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-200 | ||||||||
Vulnerability Consequences: | Obtain Information | ||||||||
References: | Source: MITRE Type: CNA CVE-2008-2432 Source: CCN Type: Novell Downloads Web site Novell iPrint Client for Windows Vista 5.06 Source: CCN Type: SA30667 Novell iPrint Client ActiveX Control Multiple Vulnerabilities Source: SECUNIA Type: Vendor Advisory 30667 Source: CCN Type: Secunia Research 25/08/2008 Novell iPrint Client ActiveX Control "GetFileList()" Information Disclosure Source: MISC Type: Vendor Advisory http://secunia.com/secunia_research/2008-30/advisory/ Source: CCN Type: Novell iPrint Wiki Web site IPrint Source: CCN Type: OSVDB ID: 50687 Novell iPrint Client Unspecified ActiveX GetFileList Method Arbitrary File Disclosure Source: BID Type: UNKNOWN 30813 Source: CCN Type: BID-30813 Novell iPrint Client ActiveX Control Multiple Remote Vulnerabilities Source: XF Type: UNKNOWN novell-iprint-getfilelist-info-disclosure(44615) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |