Junglewise Threat Intelligence

CVE-1999-0175: Novell Web Server arbitrary file read in convert.bas

CVE-1999-0175 · Severity: medium · CVSS 5 · Published 1996-07-01

Vendors: Novell.

Executive brief

A vulnerability in the Novell web server's convert.bas utility allows unauthorized users to view sensitive files on the server. This could lead to the exposure of configuration data, system files, or other private information stored on the host machine. An attacker can exploit this remotely without needing a username or password.

Technical details

The vulnerability is an arbitrary file disclosure flaw located in the convert.bas script, a component of the Novell web server. By sending a specially crafted request to this program, a remote, unauthenticated attacker can bypass intended access restrictions to read any file on the system that the web server process has permissions to access. This is likely due to improper input validation or sanitization of file paths passed to the script. The exploit is performed over the network and requires no user interaction.

Affected products

  • Novell Web Server

Timeline

  • 1996-07-01: disclosed: Initial publication date

References