Novell Convert.bas web server script vulnerability |
---|
Risk Level: | Medium | Check or Attack Name: Convert Check |
---|---|---|
Platforms: | Novell Web Server: 1.0, Common Gateway Interface (CGI) | |
Description: | The convert.bas program contains a vulnerability that allows a remote attacker to read any file on the web server. This program is included as part of the default installation of some versions of the Novell HTTP server. |
|
Remedy: | Remove the convert.bas program from the scripts directory of your web server. |
|
References: | Best-of-Security Mailing List, Novell HTTP insecure out of the box, http://www.njh.com/latest/9607/960704-01.html |
Know Your Risks |