CVE
- Id
- 986
- CVE No.
- CVE-1999-1006
- Status
- Candidate
- Description
- Groupwise web server GWWEB.EXE allows remote attackers to determine the real path of the web server via the HELP parameter.
- Phase
- Proposed (19991222)
- Votes
- ACCEPT(4) Baker, Cole, Prosser, Stracener | MODIFY(1) Frech | NOOP(2) Christey, Wall
- Comments
- Frech> XF:groupwise-web-path | Prosser> Pretty well confirmed by testing with responses to BugTraq list. | | additional ref: BugTraq ID 879 http://www.securityfocus.com/bid/879 | Christey> A later discovery almost 2 years later is at: | BUGTRAQ:20020227 SecurityOffice Security Advisory:// Novell | GroupWise Web Access Path Disclosure Vulnerability | http://marc.theaimsgroup.com/?l=bugtraq&m=101494830315071&w=2 | CD:SF-LOC might suggest merging these together.