Description
GWWEB.EXE in GroupWise Web Access 5.5, and possibly other versions, allows remote attackers to determine the full pathname of the web server via an HTTP request with an invalid HTMLVER parameter.
References (1)
Core 1
Core References
Mailing List mailing-list
x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=101494830315071&w=2
Scores
EPSS
0.0017
EPSS Percentile
38.1%
Details
Status
published
Products (1)
novell/groupwise
5.5
Published
Jun 25, 2002
Tracked Since
Feb 18, 2026