GroupWise WebAccess 5.5 with directory indexing enabled allows a remote attacker to view arbitrary directory contents via an HTTP request with a lowercase "get".
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/6988 | vdb entry |
http://www.securityfocus.com/archive/1/204875 | mailing list exploit patch vendor advisory |
http://www.securityfocus.com/bid/3188 | vdb entry |