5
CVSSv2

CVE-1999-1130

Published: 30/07/1999 Updated: 18/10/2016
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Default configuration of the search engine in Netscape Enterprise Server 3.5.1, and possibly other versions, allows remote malicious users to read the source of JHTML files by specifying a search command using the HTML-tocrec-demo1.pat pattern file.

Vulnerable Product Search on Vulmon Subscribe to Product

netscape enterprise server

Exploits

source: wwwsecurityfocuscom/bid/559/info Netscape Enterprise Server 351 and above includes a search engine by default The results it generates can be tailored using various configuration files, and one of the options is whether or not the full text of a resultant page is displayed This option is turned off by default However, even wit ...