CVE-2012-0419

Novell GroupWise <8.0 SP3, <2012 SP1 - Path Traversal

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2012-0419. PoCs published by r () b13$, juan vazquez, including Metasploit module auxiliary/scanner/http/groupwise_agents_http_traversal.

AI-analyzed exploit summary This Metasploit module exploits a directory traversal vulnerability in Novell Groupwise's web interface (Post Office and MTA agents) to retrieve arbitrary files. It sends a crafted HTTP request with traversal sequences to access files outside the intended directory.

Description

Directory traversal vulnerability in the agent HTTP interfaces in Novell GroupWise 8.0 before Support Pack 3 and 2012 before Support Pack 1 allows remote attackers to read arbitrary files via directory traversal sequences in a request.

Exploits (1)

metasploit WORKING POC
by r () b13$, juan vazquez · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/scanner/http/groupwise_agents_http_traversal.rb

This Metasploit module exploits a directory traversal vulnerability in Novell Groupwise's web interface (Post Office and MTA agents) to retrieve arbitrary files. It sends a crafted HTTP request with traversal sequences to access files outside the intended directory.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Novell Groupwise 8.02 HP2
No auth needed
Prerequisites: Network access to the Groupwise HTTP interface (port 7180/7181) · Knowledge of the target file path
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Issue Tracking x_refsource_confirm
https://bugzilla.novell.com/show_bug.cgi?id=756330
Mailing List mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2012/Sep/161
Issue Tracking x_refsource_confirm
https://bugzilla.novell.com/show_bug.cgi?id=756924
Vendor Advisory x_refsource_confirm
http://www.novell.com/support/kb/doc.php?id=7010772
Third Party Advisory mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2012-09/0106.html

Scores

EPSS 0.4184
EPSS Percentile 98.5%

Details

CWE
CWE-22
Status published
Products (5)
novell/groupwise 8.0
novell/groupwise 8.00 hp1 (3 CPE variants)
novell/groupwise 8.01 (2 CPE variants)
novell/groupwise 8.02 (4 CPE variants)
novell/groupwise 2012
Published Sep 28, 2012
Tracked Since Feb 18, 2026