CVE-1999-0239: High severity Netscape Fasttrack Server vulnerability

Published Jan 1, 1998
·
Updated

Netscape FastTrack Web server lists files when a lowercase "get" command is used instead of an uppercase GET.

Affected Software

1 affected component
Netscape Fasttrack Server=3.01

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Remove

    Remove Netscape FastTrack Server from your environment.

    Uninstall or replace the Netscape FastTrack Server if it cannot be patched; migrate content to a supported web server or a vendor-fixed version when available.

  2. Configuration

    Disable directory listing / automatic index generation so the server will not return file lists when a lowercase 'get' command is used.

    Netscape FastTrack Server directory_listing = disabled
  3. Compensating control

    Restrict access to the affected web server to trusted IP addresses using a firewall, network ACLs, or a reverse proxy/WAF until an official vendor fix is applied.

  4. Operational

    Monitor web server access logs for requests using a lowercase 'get' and review any returned directory listings for sensitive data exposure; perform incident response if disclosure is detected.

Event History

Jan 1, 1998
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
DescriptionSeverityWeaknessAffected Software
Sep 29, 1999
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-1999-0239?

The severity of CVE-1999-0239 is typically considered low, as it primarily involves improper case handling in HTTP requests.

2

How do I fix CVE-1999-0239?

To fix CVE-1999-0239, ensure that the Netscape FastTrack Server is updated to a version that handles case sensitivity properly.

3

What systems are affected by CVE-1999-0239?

CVE-1999-0239 affects the Netscape FastTrack Server version 3.01.

4

What type of vulnerability is CVE-1999-0239?

CVE-1999-0239 is classified as a server misconfiguration vulnerability due to improper handling of HTTP command case.

5

Can CVE-1999-0239 lead to data exposure?

Yes, CVE-1999-0239 can potentially lead to data exposure by allowing unauthorized file listings through the web server.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203