Arbitrary File Disclosure Vulnerability in Novell GroupWise 5.5,6
A vulnerability exists in Novell’s GroupWise server that lets an attacker view files located anywhere on the server.
October 16, 2001
Reported October 16, 2001, byMike Shema.
VERSION AFFECTED
Novell GroupWise 5.5, 6.0 for Windows 2000
DESCRIPTION
Avulnerability exists in Novell’s GroupWise server that lets an attacker viewfiles located anywhere on the server. The servlet “webacc” located in/servlet/ typically accesses templates located in webroot. However, if anattacker knows the filename and location and appends the file with a nullcharacter, the servlet also permits full directory-path traversal.
DEMONSTRATION
Mike Shema provided the following scenario asproof-of-concept. By typing the following into the address window of an Internetbrowser, a user can display the contents of boot.ini.
http://server:port/servlet/webacc?User.html=../../../../../../../../boot.ini%00
VENDOR RESPONSE
Thevendor, Novell, recommends that usersobtain a fix available through regular support channels.
CREDIT
Discovered by MikeShema of Foundstone.
About the Author
You May Also Like