5
CVSSv2

CVE-2002-1042

Published: 04/10/2002 Updated: 05/09/2008
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Directory traversal vulnerability in search engine for iPlanet web server 6.0 SP2 and 4.1 SP9, and Netscape Enterprise Server 3.6, when running on Windows platforms, allows remote malicious users to read arbitrary files via ..\ (dot-dot backslash) sequences in the NS-query-pat parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

sun iplanet web server 4.1

netscape enterprise server 3.6

sun one application server 6.0

sun one web server 6.0

Exploits

source: wwwsecurityfocuscom/bid/5191/info The iPlanet Web Server search engine is prone to a file disclosure vulnerability It is possible for remote attackers to make requests to the search engine which will cause arbitrary readable files on the host running the vulnerable software to be disclosed to the attacker This issue was reporte ...