CVE-2008-5696 Information

Description

Novell NetWare 6.5 before Support Pack 8 when an OES2 Linux server is installed into the NDS tree does not require a password for the ApacheAdmin console which allows remote attackers to reconfigure the Apache HTTP Server via console operations.

Reference

http://secunia.com/advisories/32989 http://www.novell.com/support/viewContent.do?externalId=7001907 http://www.securityfocus.com/bid/32657 http://www.securitytracker.com/id?1021350 http://www.vupen.com/english/advisories/2008/3368 https://exchange.xforce.ibmcloud.com/vulnerabilities/47104

Share on: