Vulnerabilities > CVE-2000-0237 - Unspecified vulnerability in Netscape Enterprise Server 3.5/3.6

047910
CVSS 6.4 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
NONE
network
low complexity
netscape
nessus

Summary

Netscape Enterprise Server with Web Publishing enabled allows remote attackers to list arbitrary directories via a GET request for the /publisher directory, which provides a Java applet that allows the attacker to browse the directories.

Vulnerable Configurations

Part Description Count
Application
Netscape
2

Nessus

NASL familyWeb Servers
NASL idDDI_DIRECTORY_SCANNER.NASL
descriptionThis plugin attempts to determine the presence of various common directories on the remote web server. By sending a request for a directory, the web server response code indicates if it is a valid directory or not.
last seen2020-06-01
modified2020-06-02
plugin id11032
published2002-06-26
reporterThis script is Copyright (C) 2002-2013 Digital Defense Inc.
sourcehttps://www.tenable.com/plugins/nessus/11032
titleWeb Server Directory Enumeration