Novell Convert.bas web server script vulnerability

Risk Level: Medium risk vulnerability  Medium

Check or Attack Name: Convert Check

Platforms: Novell Web Server: 1.0, Common Gateway Interface (CGI)
Description:

The convert.bas program contains a vulnerability that allows a remote attacker to read any file on the web server. This program is included as part of the default installation of some versions of the Novell HTTP server.

Remedy:

Remove the convert.bas program from the scripts directory of your web server.

References:

Best-of-Security Mailing List, Novell HTTP insecure out of the box, http://www.njh.com/latest/9607/960704-01.html


X-Force Logo
Know Your Risks