webadmin-apache.conf in Novell Web Manager of Novell NetWare 6.5 uses an uppercase Alias tag with an inconsistent lowercase directory tag for a volume, which allows remote attackers to bypass access control to the WEB-INF folder.
References
Configurations
Configuration 1 (hide)
|
History
20 Nov 2024, 23:54
Type | Values Removed | Values Added |
---|---|---|
References | () http://secunia.com/advisories/12049 - Vendor Advisory | |
References | () http://securitytracker.com/id?1011012 - | |
References | () http://support.novell.com/cgi-bin/search/searchtid.cgi?/10094233.htm - | |
References | () http://www.osvdb.org/9103 - | |
References | () http://www.securityfocus.com/bid/11000 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/40478 - |
Information
Published : 2004-12-31 05:00
Updated : 2024-11-20 23:54
NVD link : CVE-2004-2734
Mitre link : CVE-2004-2734
CVE.ORG link : CVE-2004-2734
JSON object : View
Products Affected
novell
- netware
CWE
CWE-287
Improper Authentication