Vulnerability Description
Novell NetWare Enterprise Web Server 5.1 and 6.0 allows remote attackers to obtain sensitive server information, including the internal IP address, via a direct request to (1) snoop.jsp, (2) SnoopServlet, (3) env.bas, or (4) lcgitest.nlm.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Novell | Netware | 5.1 |
References
- http://marc.info/?l=bugtraq&m=107487862304440&w=2
- http://secunia.com/advisories/10711
- http://www.osvdb.org/3715
- http://www.osvdb.org/3720
- http://www.osvdb.org/3721
- http://www.osvdb.org/3722
- http://www.osvdb.org/4952
- http://www.securityfocus.com/bid/9479
- https://exchange.xforce.ibmcloud.com/vulnerabilities/14921
- http://marc.info/?l=bugtraq&m=107487862304440&w=2
- http://secunia.com/advisories/10711
- http://www.osvdb.org/3715
- http://www.osvdb.org/3720
- http://www.osvdb.org/3721
- http://www.osvdb.org/3722
FAQ
What is CVE-2004-2104?
CVE-2004-2104 is a vulnerability with a CVSS score of 5.0 (MEDIUM). Novell NetWare Enterprise Web Server 5.1 and 6.0 allows remote attackers to obtain sensitive server information, including the internal IP address, via a direct request to (1) snoop.jsp, (2) SnoopServ...
How severe is CVE-2004-2104?
CVE-2004-2104 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2004-2104?
Check the references section above for vendor advisories and patch information. Affected products include: Novell Netware.