CVE
- Id
- 4733
- CVE No.
- CVE-2002-0341
- Status
- Candidate
- Description
- GWWEB.EXE in GroupWise Web Access 5.5, and possibly other versions, allows remote attackers to determine the full pathname of the web server via an HTTP request with an invalid HTMLVER parameter.
- Phase
- Proposed (20020502)
- Votes
- MODIFY(1) Frech | NOOP(5) Christey, Cole, Cox, Foat, Wall
- Comments
- Frech> XF:groupwise-arg-path-disclosure(8311) | Christey> Desc: "... which leaks the pathname in an error message."