FileUploadServlet in the Administration service in Novell GroupWise 2014 before SP1 allows remote attackers to read or write to arbitrary files via the poLibMaintenanceFileSave parameter, aka ZDI-CAN-2287.
References
Configurations
Information
Published : 2014-08-29 02:55
Updated : 2017-01-06 18:59
NVD link : CVE-2014-0600
Mitre link : CVE-2014-0600
JSON object : View
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
Products Affected
novell
- groupwise