CNCVE编号:CNCVE-20020012 CVE编号: 安全级别:中 漏洞中文描述: Novell GroupWise是Novell出品的一种目录服务系统。GroupWise Web Access 5.6所带的某些CGI在处理一些非预期的参数时会返回错误信息,其中包含了webroot目录的绝对路径信息,攻击者可能利用这些信息发动进一步攻击。 漏洞英文描述: Novell GroupWise is an email, calendaring and collaborative application available from Novell. It is designed for use on the Microsoft Windows and Novell Netware platforms, and includes a web access component for use through a web browser. A vulnerability has been reported in some versions of GroupWise. Reportedly, if a maliciously formatted web request is submitted to the GWWEB.EXE cgi process, an error message will be returned. This error message will include the full path of the script. Other versions of GroupWise may share this vulnerability. This has not, however, been confirmed. 漏洞参考: http://www.novell.com 系统类型: 其他 漏洞类型:设计错误