PT-1999-1587 · Netscape · Netscape Enterprise Server
Published
1999-07-30
·
Updated
2016-10-18
·
CVE-1999-1130
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Netscape Enterprise Server version 3.5.1
Description
The default configuration of the search engine in the affected software allows remote attackers to read the source of JHTML files by specifying a search command using the HTML-tocrec-demo1.pat pattern file.
Recommendations
For Netscape Enterprise Server version 3.5.1, consider changing the default configuration of the search engine to prevent remote attackers from reading the source of JHTML files. As a temporary workaround, restrict access to the search functionality until a more permanent solution is implemented.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Netscape Enterprise Server