BlackKite: Home
Menu

PUBLISHED DATE: April 11, 2003CVE-2002-1437:
Directory Traversal Vulnerability

CVSS:
5
EPSS:
597.50%
Exploitability:
10
In KEV:
No
Description

Directory traversal vulnerability in the web handler for Perl 5.003 on Novell NetWare 5.1 and NetWare 6 allows remote attackers to read arbitrary files via an HTTP request containing "..%5c" (URL-encoded dot-dot backslash) sequences.

Products
Questions to Ask Vendors
  1. Can you confirm whether your systems are affected by CVE-2002-1437, and if so, what steps are you currently taking to mitigate this vulnerability?
  2. What is your estimated timeline for fully resolving CVE-2002-1437 in your products or services, and how will you communicate updates on this issue to us as your customer?
Recommended Actions
References

Ready to get results you can trust?