GWWEB.EXE in GroupWise Web Access 5.5, and possibly other versions, allows remote attackers to determine the full pathname of the web server via an HTTP request with an invalid HTMLVER parameter.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Groupwise | Novell | 5.5 (including) | 5.5 (including) |