First published: Fri Jul 30 1999(Updated: )
Default configuration of the search engine in Netscape Enterprise Server 3.5.1, and possibly other versions, allows remote attackers to read the source of JHTML files by specifying a search command using the HTML-tocrec-demo1.pat pattern file.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Netscape Enterprise Server | <=3.5.1 | |
<=3.5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-1999-1130 is considered to be moderate due to its potential impact on data exposure.
To fix CVE-1999-1130, reconfigure the search engine settings in Netscape Enterprise Server to restrict access to JHTML files.
CVE-1999-1130 affects Netscape Enterprise Server versions up to and including 3.5.1.
Yes, CVE-1999-1130 can be exploited remotely by attackers to read the source of JHTML files.
CVE-1999-1130 is related to improper file access permissions in the default configuration.