Description
Groupwise web server GWWEB.EXE allows remote attackers to read arbitrary files with .htm extensions via a .. (dot dot) attack using the HELP parameter.
Affected products
- netscape / enterprise_server3.0.7a – 3.0.7a
- Novell / groupwise5.2 – 5.2
- Novell / groupwise5.5 – 5.5