Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2010-4715 | First vendor Publication | 2011-01-31 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:L/Au:N/C:P/I:N/A:N) | |||
---|---|---|---|
Cvss Base Score | 5 | Attack Range | Network |
Cvss Impact Score | 2.9 | Attack Complexity | Low |
Cvss Expoit Score | 10 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Multiple directory traversal vulnerabilities in the (1) WebAccess Agent and (2) Document Viewer Agent components in Novell GroupWise before 8.02HP allow remote attackers to read arbitrary files via unspecified vectors. NOTE: some of these details are obtained from third party information. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4715 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE/SANS Top 25) |
CPE : Common Platform Enumeration
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
69138 | Novell GroupWise Multiple Agent Unspecified Traversal Arbitrary File Access Novell GroupWise contains a flaw that allows a local attacker to traverse outside of a restricted path. The issue is due to WebAccess Agent and the Document Viewer Agent not properly sanitizing user input, specifically directory traversal style attacks (e.g., ../../) supplied via an unspecified parameter. This directory traversal attack would allow the attacker to download arbitrary files. |
Snort® IPS/IDS
Date | Description |
---|---|
2014-01-10 | Novell GroupWise Internet Agent RRULE parsing buffer overflow attempt RuleID : 18768 - Revision : 20 - Type : SERVER-MAIL |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2010-11-23 | Name : The remote web server is susceptible to a directory traversal attack. File : groupwise_dva_arbitrary_file_download.nasl - Type : ACT_ATTACK |
2010-11-23 | Name : The remote host has an application that is susceptible to a directory travers... File : groupwise_webaccess_802_hp1.nasl - Type : ACT_GATHER_INFO |
2010-11-23 | Name : The remote web server is susceptible to a directory traversal attack. File : groupwise_webaccess_arbitrary_file_download.nasl - Type : ACT_ATTACK |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:06:16 |
|
2024-11-28 12:24:01 |
|
2021-05-04 12:13:15 |
|
2021-04-22 01:13:43 |
|
2020-05-23 01:43:26 |
|
2020-05-23 00:27:18 |
|
2016-04-26 20:19:29 |
|
2014-02-17 10:59:08 |
|
2014-01-19 21:27:19 |
|
2013-05-10 23:39:16 |
|