Vulnerabilities > CVE-2001-0250 - Unspecified vulnerability in Netscape Enterprise Server 3.0/4.0

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
netscape
nessus
exploit available

Summary

The Web Publishing feature in Netscape Enterprise Server 4.x and earlier allows remote attackers to list arbitrary directories under the web server root via the INDEX command.

Vulnerable Configurations

Part Description Count
Application
Netscape
2

Exploit-Db

descriptionNetscape Enterprise Server 3.0/4.0 'Index' Disclosure Vulnerability. CVE-2001-0250. Remote exploits for multiple platform
idEDB-ID:20591
last seen2016-02-02
modified2001-01-24
published2001-01-24
reporterSecurity Research Team
sourcehttps://www.exploit-db.com/download/20591/
titleNetscape Enterprise Server 3.0/4.0 - 'Index' Disclosure Vulnerability

Nessus

NASL familyWeb Servers
NASL idNETSCAPE_ENTREPRISE_INDEX.NASL
descriptionThe remote web server gives a file listing when it is issued the command : INDEX / HTTP/1.1 An attacker may use this flaw to discover the internal structure of your website, or to discover supposedly hidden files.
last seen2020-06-01
modified2020-06-02
plugin id10691
published2001-06-15
reporterThis script is Copyright (C) 2001-2018 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/10691
titleNetscape Enterprise Web Publishing INDEX Command Arbitrary Directory Listing