CVE-1999-1130: Medium severity Netscape Enterprise Server vulnerability
Default configuration of the search engine in Netscape Enterprise Server 3.5.1, and possibly other versions, allows remote attackers to read the source of JHTML files by specifying a search command using the HTML-tocrec-demo1.pat pattern file.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Remove or disable the HTML-tocrec-demo1.pat pattern file from the search engine's pattern directory or configuration so it cannot be specified in search commands.
Netscape Enterprise Server search engine pattern file 'HTML-tocrec-demo1.pat' = remove or disable - Configuration
Reconfigure the search engine default configuration to prevent search commands from reading or returning the source of .jhtml/JHTML files (do not treat JHTML files as retrievable source content).
Netscape Enterprise Server search engine default search behavior for JHTML files = do not allow returning JHTML source - Compensating control
Restrict access to the search engine/search command interface to trusted IPs or internal networks via firewall, ACLs, or similar network controls until the configuration is corrected.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-1130?
The severity of CVE-1999-1130 is considered to be moderate due to its potential impact on data exposure.
How do I fix CVE-1999-1130?
To fix CVE-1999-1130, reconfigure the search engine settings in Netscape Enterprise Server to restrict access to JHTML files.
What versions are affected by CVE-1999-1130?
CVE-1999-1130 affects Netscape Enterprise Server versions up to and including 3.5.1.
Can CVE-1999-1130 be exploited remotely?
Yes, CVE-1999-1130 can be exploited remotely by attackers to read the source of JHTML files.
Is CVE-1999-1130 related to file permissions?
CVE-1999-1130 is related to improper file access permissions in the default configuration.