Novell Convert.bas web server script vulnerability

Risk Level: Medium risk vulnerability  Medium

Check or Attack Name: Convert Check

Platforms: Novell Web Server: 1.0, Common Gateway Interface (CGI)

The convert.bas program contains a vulnerability that allows a remote attacker to read any file on the web server. This program is included as part of the default installation of some versions of the Novell HTTP server.


Remove the convert.bas program from the scripts directory of your web server.


Best-of-Security Mailing List, Novell HTTP insecure out of the box,

X-Force Logo
Know Your Risks