CVE-1999-1130: Medium severity Netscape Enterprise Server vulnerability

Published Jul 30, 1999
·
Updated

Default configuration of the search engine in Netscape Enterprise Server 3.5.1, and possibly other versions, allows remote attackers to read the source of JHTML files by specifying a search command using the HTML-tocrec-demo1.pat pattern file.

Affected Software

1 affected component
Netscape Enterprise Server<=3.5.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Remove or disable the HTML-tocrec-demo1.pat pattern file from the search engine's pattern directory or configuration so it cannot be specified in search commands.

    Netscape Enterprise Server search engine pattern file 'HTML-tocrec-demo1.pat' = remove or disable
  2. Configuration

    Reconfigure the search engine default configuration to prevent search commands from reading or returning the source of .jhtml/JHTML files (do not treat JHTML files as retrievable source content).

    Netscape Enterprise Server search engine default search behavior for JHTML files = do not allow returning JHTML source
  3. Compensating control

    Restrict access to the search engine/search command interface to trusted IPs or internal networks via firewall, ACLs, or similar network controls until the configuration is corrected.

Event History

Jul 30, 1999
CVE Published
04:00 AM
Data Sourced
via NVD·04:00 AM
DescriptionSeverityAffected Software
Sep 12, 2001
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-1999-1130?

The severity of CVE-1999-1130 is considered to be moderate due to its potential impact on data exposure.

2

How do I fix CVE-1999-1130?

To fix CVE-1999-1130, reconfigure the search engine settings in Netscape Enterprise Server to restrict access to JHTML files.

3

What versions are affected by CVE-1999-1130?

CVE-1999-1130 affects Netscape Enterprise Server versions up to and including 3.5.1.

4

Can CVE-1999-1130 be exploited remotely?

Yes, CVE-1999-1130 can be exploited remotely by attackers to read the source of JHTML files.

5

Is CVE-1999-1130 related to file permissions?

CVE-1999-1130 is related to improper file access permissions in the default configuration.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203