CVE-2004-2104
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
31/12/2004
Last modified:
03/04/2025
Description
Novell NetWare Enterprise Web Server 5.1 and 6.0 allows remote attackers to obtain sensitive server information, including the internal IP address, via a direct request to (1) snoop.jsp, (2) SnoopServlet, (3) env.bas, or (4) lcgitest.nlm.
Impact
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:novell:netware:5.1:*:*:*:*:*:*:* | ||
| cpe:2.3:o:novell:netware:6.0:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://marc.info/?l=bugtraq&m=107487862304440&w=2
- http://secunia.com/advisories/10711
- http://www.osvdb.org/3715
- http://www.osvdb.org/3720
- http://www.osvdb.org/3721
- http://www.osvdb.org/3722
- http://www.osvdb.org/4952
- http://www.securityfocus.com/bid/9479
- https://exchange.xforce.ibmcloud.com/vulnerabilities/14921
- http://marc.info/?l=bugtraq&m=107487862304440&w=2
- http://secunia.com/advisories/10711
- http://www.osvdb.org/3715
- http://www.osvdb.org/3720
- http://www.osvdb.org/3721
- http://www.osvdb.org/3722
- http://www.osvdb.org/4952
- http://www.securityfocus.com/bid/9479
- https://exchange.xforce.ibmcloud.com/vulnerabilities/14921



