Subscribe to Windows IT Pro
October 17, 2001 12:00 AM

Arbitrary File Disclosure Vulnerability in Novell GroupWise 5.5,6

Windows IT Pro
InstantDoc ID #22917
Rating: (0)

Reported October 16, 2001, by Mike Shema.

VERSION AFFECTED

  • Novell GroupWise 5.5, 6.0 for Windows 2000

 

DESCRIPTION
A vulnerability exists in Novell’s GroupWise server that lets an attacker view files located anywhere on the server. The servlet “webacc” located in /servlet/ typically accesses templates located in webroot. However, if an attacker knows the filename and location and appends the file with a null character, the servlet also permits full directory-path traversal.

 

DEMONSTRATION

Mike Shema provided the following scenario as proof-of-concept. By typing the following into the address window of an Internet browser, a user can display the contents of boot.ini.

 

http://server:port/servlet/webacc?User.html=../../../../../../../../boot.ini%00

 

VENDOR RESPONSE

The vendor, Novell, recommends that users obtain a fix available through regular support channels.

 

CREDIT
Discovered by Mike Shema of Foundstone.

Related Content:

ARTICLE TOOLS

Comments
  • Dee Bantz
    11 years ago
    Oct 18, 2001




    Your article maybe should read "... Novell GroupWise version 5.5 Enhancement Pack and Novell GroupWise 6..."? Some of us out here have GroupWise 5.5 without the Enhancement Pack. (Quote was from Novell TID 2960440)

You must log on before posting a comment.

Are you a new visitor? Register Here

advertisement

advertisement

Windows is a trademark of the Microsoft group of companies. Windows IT Pro is used by Penton Media Inc. under license from owner.