Lucene search

K
cveMitreCVE-2002-1437
HistorySep 01, 2004 - 4:00 a.m.

CVE-2002-1437

2004-09-0104:00:00
mitre
web.nvd.nist.gov
25
cve-2002-1437
directory traversal
perl
netware
remote attackers
http request
nvd

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

6.8

Confidence

Low

EPSS

0.023

Percentile

89.7%

Directory traversal vulnerability in the web handler for Perl 5.003 on Novell NetWare 5.1 and NetWare 6 allows remote attackers to read arbitrary files via an HTTP request containing “…%5c” (URL-encoded dot-dot backslash) sequences.

Affected configurations

Nvd
Node
novellnetwareMatch5.1
OR
novellnetwareMatch5.1sp4
OR
novellnetwareMatch6.0
OR
novellnetwareMatch6.0sp1
VendorProductVersionCPE
novellnetware5.1cpe:2.3:o:novell:netware:5.1:*:*:*:*:*:*:*
novellnetware5.1cpe:2.3:o:novell:netware:5.1:sp4:*:*:*:*:*:*
novellnetware6.0cpe:2.3:o:novell:netware:6.0:*:*:*:*:*:*:*
novellnetware6.0cpe:2.3:o:novell:netware:6.0:sp1:*:*:*:*:*:*

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

6.8

Confidence

Low

EPSS

0.023

Percentile

89.7%

Related for CVE-2002-1437