Vulnerabilities > CVE-2000-1196 - Unspecified vulnerability in Netscape Publishingxpert 2.5

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
netscape
nessus
exploit available

Summary

PSCOErrPage.htm in Netscape PublishingXpert 2.5 before SP2 allows remote attackers to read arbitrary files by specifying the target file in the errPagePath parameter.

Vulnerable Configurations

Part Description Count
Application
Netscape
2

Exploit-Db

descriptionNetscape PublishingXPert 2.0/2.2/2.5 Local File Reading Vulnerability. CVE-2000-1196. Remote exploit for solaris platform
idEDB-ID:20966
last seen2016-02-02
modified2000-04-06
published2000-04-06
reporter\x00\x00
sourcehttps://www.exploit-db.com/download/20966/
titleNetscape PublishingXPert 2.0/2.2/2.5 - Local File Reading Vulnerability

Nessus

NASL familyCGI abuses
NASL idNETSCAPE_PUBLISHING_EXPERT_PSUSER.NASL
descriptionThe
last seen2020-06-01
modified2020-06-02
plugin id10364
published2000-04-12
reporterThis script is Copyright (C) 2000-2018 and is owned by Tenable, Inc. or an Affiliate thereof.
sourcehttps://www.tenable.com/plugins/nessus/10364
titleNetscape PSCOErrPage.htm errPagePath Parameter Traversal Arbitrary File Access