CVE-2004-2104
28Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 12%
from disclosure to weapon0 days
Published on NVDMay 27
1st PoCJan 23
exploitation probability
12%top 4% of all CVEs
observed exploitation
nono source reports it
3 public exploit(s)
Novell NetWare Enterprise Web Server 5.1 and 6.0 allows remote attackers to obtain sensitive server information, including the internal IP address, via a direct request to (1) snoop.jsp, (2) SnoopServlet, (3) env.bas, or (4) lcgitest.nlm.
Affected products
n/a · n/apublic PoCs found — 3✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/23588exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/23587exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/23586⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://marc.info/?l=bugtraq&m=107487862304440&w=2http://secunia.com/advisories/10711https://exchange.xforce.ibmcloud.com/vulnerabilities/14921http://www.osvdb.org/3715http://www.osvdb.org/3720http://www.osvdb.org/3721http://www.osvdb.org/3722http://www.osvdb.org/4952http://www.securityfocus.com/bid/9479