Show filters
80 Total Results
Displaying 41-50 of 80
Sort by:
Attacker Value
Unknown
CVE-2005-0819
Disclosure Date: May 02, 2005 (last updated February 22, 2025)
The xvesa code in Novell Netware 6.5 SP2 and SP3 allows remote attackers to redirect the xsession without authentication via a direct request to GUIMirror/Start.
0
Attacker Value
Unknown
CVE-2004-2103
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in Novell NetWare Enterprise Web Server 5.1 and 6.0 allows remote attackers to process arbitrary script or HTML as other users via (1) a malformed request for a Perl program with script in the filename, (2) the User.id parameter to the webacc servlet, (3) the GWAP.version parameter to webacc, or (4) a URL request for a .bas file with script in the filename.
0
Attacker Value
Unknown
CVE-2004-2104
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Novell NetWare Enterprise Web Server 5.1 and 6.0 allows remote attackers to obtain sensitive server information, including the internal IP address, via a direct request to (1) snoop.jsp, (2) SnoopServlet, (3) env.bas, or (4) lcgitest.nlm.
0
Attacker Value
Unknown
CVE-2004-2106
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Novell NetWare Enterprise Web Server 5.1 and 6.0 allows remote attackers to list directories via a direct request to (1) /com/, (2) /com/novell/, (3) /com/novell/webaccess, or (4) /ns-icons/.
0
Attacker Value
Unknown
CVE-2004-2414
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Novell NetWare 6.5 SP 1.1, when installing or upgrading using the Overlay CDs and performing a custom installation with OpenSSH, includes sensitive password information in the (1) NIOUTPUT.TXT and (2) NI.LOG log files, which might allow local users to obtain the passwords.
0
Attacker Value
Unknown
CVE-2004-2734
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
webadmin-apache.conf in Novell Web Manager of Novell NetWare 6.5 uses an uppercase Alias tag with an inconsistent lowercase directory tag for a volume, which allows remote attackers to bypass access control to the WEB-INF folder.
0
Attacker Value
Unknown
CVE-2004-2105
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
The webacc servlet in Novell NetWare Enterprise Web Server 5.1 and 6.0 allows remote attackers to read arbitrary .htt files via a full pathname in the error parameter.
0
Attacker Value
Unknown
CVE-2003-0976
Disclosure Date: December 15, 2003 (last updated February 22, 2025)
NFS Server (XNFS.NLM) for Novell NetWare 6.5 does not properly enforce sys:\etc\exports when hostname aliases from sys:etc\hosts file are used, which could allow users to mount file systems when XNFS should deny the host.
0
Attacker Value
Unknown
CVE-2003-1150
Disclosure Date: October 27, 2003 (last updated February 22, 2025)
Buffer overflow in the portmapper service (PMAP.NLM) in Novell NetWare 6 SP3 and ZenWorks for Desktops 3.2 SP2 through 4.0.1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via unknown attack vectors.
0
Attacker Value
Unknown
CVE-2003-0562
Disclosure Date: August 27, 2003 (last updated February 22, 2025)
Buffer overflow in the CGI2PERL.NLM PERL handler in Novell Netware 5.1 and 6.0 allows remote attackers to cause a denial of service (ABEND) via a long input string.
0