Groupewise Web Interface

From: Sacha Faust Bourque (sfaustat_private)
Date: Sun Dec 19 1999 - 15:08:00 PST

  • Next message: Holger van Lengerich: "Re: Reinventing the wheel (aka "Decoding Netscape Mail passwords")"

    Problems found with GroupeWise web server ( Novell was contacted 3 weeks ago
    and no reply )
    -----------------------------------------------------------------
    
    1. The help argument in GWWEB.EXE reveal full web path on the server
    2. anyone can read a .htm file on the system with the GWWEB.EXE and the HELP
    argument.
    
    Example:
    
    1. ( full web server path )
    
    By sending http://server/cgi-bin/GW5/GWWEB.EXE?HELP=bad-request
    the server will reply
    Could not find file SYS:WEB\CGI-BIN\GW5\US\HTML3\HELP\BAD-REQUEST.HTM
    2. ( read any .htm file )
    
    by sending http://server/cgi-bin/GW5/GWWEB.EXE?HELP=../../../../../index   (
    refering to the path returned in the previous example ). You will see the
    main web site interface.
    
    We did some intensive test with the HELP trying to get rid of the .htm that
    it happens and we were unable to
    get rid of it. We are currently testing other arguments sent to GWWEB.EXE.
    
    This was tested on GroupWise 5.2 and 5.5 .
    
    
    This was found by Laurent Hollo and me.
    
    Sacha Faust Bourque
    sfaustat_private
    



    This archive was generated by hypermail 2b30 : Fri Apr 13 2001 - 15:21:59 PDT