Vulnerabilities > CVE-2000-1075

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
netscape
sun
nessus
exploit available

Summary

Directory traversal vulnerability in iPlanet Certificate Management System 4.2 and Directory Server 4.12 allows remote attackers to read arbitrary files via a .. (dot dot) attack in the Agent, End Entity, or Administrator services.

Vulnerable Configurations

Part Description Count
Application
Netscape
1
Application
Sun
1

Exploit-Db

  • descriptioniPlanet Certificate Management System 4.2 for Windows NT 4.0 Directory Traversal. CVE-2000-1075. Remote exploit for windows platform
    idEDB-ID:20324
    last seen2016-02-02
    modified2000-10-25
    published2000-10-25
    reporterCORE-SDI
    sourcehttps://www.exploit-db.com/download/20324/
    titleiPlanet Certificate Management System 4.2 - Directory Traversal
  • descriptionNetscape Directory Server 4.12 Directory Server Directory Traversal Vulnerability. CVE-2000-1075. Remote exploit for windows platform
    idEDB-ID:20325
    last seen2016-02-02
    modified2000-10-25
    published2000-10-25
    reporterCORE-SDI
    sourcehttps://www.exploit-db.com/download/20325/
    titleNetscape Directory Server 4.12 - Directory Server Directory Traversal Vulnerability

Nessus

  • NASL familyWeb Servers
    NASL idIPLANET_DIR_SERV.NASL
    descriptionThere is a bug in the remote iPlanet web server that allows a user to read arbitrary files on the remote host. To exploit this flaw, an attacker needs to prepend
    last seen2020-06-01
    modified2020-06-02
    plugin id10589
    published2001-01-08
    reporterThis script is Copyright (C) 2001-2018 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/10589
    titleiPlanet Directory Server Traversal Arbitrary File Access
  • NASL familyWeb Servers
    NASL idIPLANET_TRAVERSAL.NASL
    descriptionIt is possible to read arbitrary files on the remote server by prepending /ca/\../\../ in front on the file name.
    last seen2020-06-01
    modified2020-06-02
    plugin id10683
    published2001-05-29
    reporterThis script is Copyright (C) 2001-2018 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/10683
    titleiPlanet Certificate Management Traversal Arbitrary File Access

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/32497/accipiter.txt
idPACKETSTORM:32497
last seen2016-12-05
published2004-01-09
reporterMark Bassett
sourcehttps://packetstormsecurity.com/files/32497/accipiter.txt.html
titleaccipiter.txt