First published: Sat Feb 01 1997(Updated: )
The view-source CGI program allows remote attackers to read arbitrary files via a .. (dot dot) attack.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Netscape Communicator | =4.05 | |
Netscape Communicator | =4.07 | |
Netscape Communicator | =4.51 | |
Netscape Communicator | =4.06 | |
Netscape Communicator | =4.0 | |
Netscape Communicator | =4.6 | |
Netscape Communicator | =4.5 | |
=4.0 | ||
=4.05 | ||
=4.5 | ||
=4.06 | ||
=4.6 | ||
=4.07 | ||
=4.51 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-1999-0174 is considered a high-severity vulnerability that allows remote attackers to read arbitrary files on affected systems.
To fix CVE-1999-0174, upgrade to a patched version of Netscape Communicator beyond 4.51 where this vulnerability is resolved.
CVE-1999-0174 affects Netscape Communicator versions 4.0 through 4.51.
The attack in CVE-1999-0174 exploits the view-source CGI program using a dot dot (..) path traversal to access restricted files.
Using an affected version of Netscape Communicator is risky as it exposes systems to potential attacks, and it is highly recommended to upgrade to a secure version.