Vulnerabilities > CVE-2002-1042

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
netscape
sun
nessus
exploit available

Summary

Directory traversal vulnerability in search engine for iPlanet web server 6.0 SP2 and 4.1 SP9, and Netscape Enterprise Server 3.6, when running on Windows platforms, allows remote attackers to read arbitrary files via ..\ (dot-dot backslash) sequences in the NS-query-pat parameter.

Vulnerable Configurations

Part Description Count
Application
Netscape
1
Application
Sun
25

Exploit-Db

descriptioniPlanet Web Server 4.1 Search Component File Disclosure Vulnerability. CVE-2002-1042. Remote exploits for multiple platform
idEDB-ID:21603
last seen2016-02-02
modified2002-07-09
published2002-07-09
reporterQualys Corporation
sourcehttps://www.exploit-db.com/download/21603/
titleiPlanet Web Server 4.1 - Search Component File Disclosure Vulnerability

Nessus

NASL familyWeb Servers
NASL idIPLANET_SEARCH.NASL
descriptionAn attacker may be able to read arbitrary files on the remote web server, using the
last seen2020-06-01
modified2020-06-02
plugin id11043
published2002-07-10
reporterThis script is Copyright (C) 2002-2018 and is owned by Tenable, Inc. or an Affiliate thereof.
sourcehttps://www.tenable.com/plugins/nessus/11043
titleiPlanet Search Engine search CGI Arbitrary File Access