5
CVSSv2

CVE-2000-0676

Published: 20/10/2000 Updated: 10/09/2008
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Netscape Communicator and Navigator 4.04 up to and including 4.74 allows remote malicious users to read arbitrary files by using a Java applet to open a connection to a URL using the "file", "http", "https", and "ftp" protocols, as demonstrated by Brown Orifice.

Vulnerable Product Search on Vulmon Subscribe to Product

netscape communicator 4.0

netscape communicator 4.05

netscape communicator 4.07

netscape communicator 4.6

netscape communicator 4.72

netscape communicator 4.74

netscape communicator 4.08

netscape communicator 4.5

netscape communicator 4.5_beta

netscape communicator 4.51

netscape communicator 4.04

netscape communicator 4.06

netscape communicator 4.61

netscape communicator 4.73

Exploits

source: wwwsecurityfocuscom/bid/1546/info A flaw in Netscape Communicator's implementation of Java allows malicious applets to read any resource reachable via a URL from the local machine by using the netscapenetURLConnection and netscapenetURLInputSteam classes This allows malicious applets to read local files as well as download da ...