← Vulnerability feed

Vulnerability record · CVE-2002-1437 · published 11 April 2003

CVE-2002-1437: Novell netware vulnerability

Novell · Netware

Directory traversal vulnerability in the web handler for Perl 5.003 on Novell NetWare 5.1 and NetWare 6 allows remote attackers to read arbitrary files via an HTTP request containing "..%5c" (URL-encoded dot-dot backslash) sequences.

5.0 CVSS 2.0 Medium EPSS 17% · top 3.0%
5.0CVSS 2.0 base score
17%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References
16 Jun 2026Last modified by NVD

Description

Directory traversal vulnerability in the web handler for Perl 5.003 on Novell NetWare 5.1 and NetWare 6 allows remote attackers to read arbitrary files via an HTTP request containing "..%5c" (URL-encoded dot-dot backslash) sequences.

AV:N/AC:L/Au:N/C:P/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2002-1437 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2010-4227Novell netware memory buffer overflow vulnerabilityThe xdrDecodeString function in XNFS.NLM in Novell Netware 6.5 before SP8 allows remote attackers to cause a denial of service (abend) or execute arb…EPSS 17%10.0CVE-2010-2351Novell netware memory buffer overflow vulnerabilityStack-based buffer overflow in the CIFS.NLM driver in Netware SMB 1.0 for Novell Netware 6.5 SP8 and earlier allows remote attackers to execute arbit…EPSS 16%10.0CVE-2003-1595Novell netware ftp server permissions and access controls vulnerabilityNWFTPD.nlm before 5.04.05 in the FTP server in Novell NetWare 6.5 does not properly perform "intruder detection," which has unspecified impact and at…EPSS 1.7%10.0CVE-2004-2734Novell netware improper authentication vulnerabilitywebadmin-apache.conf in Novell Web Manager of Novell NetWare 6.5 uses an uppercase Alias tag with an inconsistent lowercase directory tag for a volum…EPSS 4.0%10.0CVE-1999-1086Novell netware vulnerabilityNovell 5 and earlier, when running over IPX with a packet signature level less than 3, allows remote attackers to gain administrator privileges by sp…EPSS 2.6%9.3CVE-2008-5696Novell netware vulnerabilityNovell NetWare 6.5 before Support Pack 8, when an OES2 Linux server is installed into the NDS tree, does not require a password for the ApacheAdmin c…EPSS 3.3%9.0CVE-2010-4228Novell netware memory buffer overflow vulnerabilityStack-based buffer overflow in NWFTPD.NLM before 5.10.02 in the FTP server in Novell NetWare allows remote authenticated users to execute arbitrary c…EPSS 15%7.8CVE-2010-0317Novell netware vulnerabilityNovell Netware 6.5 SP8 allows remote attackers to cause a denial of service (NULL pointer dereference, memory consumption, ABEND, and crash) via a la…EPSS 10%

Source: NIST National Vulnerability Database (record CVE-2002-1437), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.