CVE

Id
4733  
CVE No.
CVE-2002-0341  
Status
Candidate  
Description
GWWEB.EXE in GroupWise Web Access 5.5, and possibly other versions, allows remote attackers to determine the full pathname of the web server via an HTTP request with an invalid HTMLVER parameter.  
Phase
Proposed (20020502)  
Votes
MODIFY(1) Frech | NOOP(5) Christey, Cole, Cox, Foat, Wall  
Comments
Frech> XF:groupwise-arg-path-disclosure(8311) | Christey> Desc: "... which leaks the pathname in an error message."