Vulnerabilities > CVE-2002-1042

047910
CVSS 0.0 - NONE
Attack vector
UNKNOWN
Attack complexity
UNKNOWN
Privileges required
UNKNOWN
Confidentiality impact
UNKNOWN
Integrity impact
UNKNOWN
Availability impact
UNKNOWN
sun
netscape
nessus
exploit available

Summary

Directory traversal vulnerability in search engine for iPlanet web server 6.0 SP2 and 4.1 SP9, and Netscape Enterprise Server 3.6, when running on Windows platforms, allows remote attackers to read arbitrary files via ..\ (dot-dot backslash) sequences in the NS-query-pat parameter.

Vulnerable Configurations

Part Description Count
Application
Sun
25
Application
Netscape
1

Exploit-Db

descriptioniPlanet Web Server 4.1 Search Component File Disclosure Vulnerability. CVE-2002-1042. Remote exploits for multiple platform
idEDB-ID:21603
last seen2016-02-02
modified2002-07-09
published2002-07-09
reporterQualys Corporation
sourcehttps://www.exploit-db.com/download/21603/
titleiPlanet Web Server 4.1 - Search Component File Disclosure Vulnerability

Nessus

NASL familyWeb Servers
NASL idIPLANET_SEARCH.NASL
descriptionAn attacker may be able to read arbitrary files on the remote web server, using the
last seen2020-06-01
modified2020-06-02
plugin id11043
published2002-07-10
reporterThis script is Copyright (C) 2002-2018 and is owned by Tenable, Inc. or an Affiliate thereof.
sourcehttps://www.tenable.com/plugins/nessus/11043
titleiPlanet Search Engine search CGI Arbitrary File Access