CVE-1999-1357: High severity Netscape Communicator vulnerability

Published Oct 5, 1999
·
Updated

Netscape Communicator 4.04 through 4.7 (and possibly other versions) in various UNIX operating systems converts the 0x8b character to a "<" sign, and the 0x9b character to a ">" sign, which could allow remote attackers to attack other clients via cross-site scripting (CSS) in CGI programs that do not filter these characters.

Affected Software

3 affected components
Netscape Communicator=4.04
Netscape Communicator=4.51
Netscape Communicator<=4.7

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Ensure CGI programs properly filter or HTML-encode the raw byte values 0x8b and 0x9b (so they are not emitted as characters that can be transformed into '<' or '>') before including user-supplied data in HTML responses.

    CGI programs / web application output encoding filter/escape 0x8b and 0x9b bytes = escape or remove
  2. Operational

    Audit existing CGI scripts and web applications for places where untrusted input is included in HTML output; patch or update those scripts to apply proper output encoding/escaping for HTML contexts and re-test to confirm the characters 0x8b and 0x9b cannot lead to injected '<' or '>' characters.

Event History

Oct 5, 1999
CVE Published
04:00 AM
Data Sourced
via NVD·04:00 AM
DescriptionSeverityAffected Software
Sep 12, 2001
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-1999-1357?

CVE-1999-1357 has been classified as a moderate severity vulnerability.

2

What does CVE-1999-1357 affect?

CVE-1999-1357 affects Netscape Communicator versions 4.04 through 4.7 on various UNIX operating systems.

3

How do I fix CVE-1999-1357?

To mitigate CVE-1999-1357, upgrade to a version of Netscape Communicator that is beyond 4.7.

4

What types of attacks can CVE-1999-1357 enable?

CVE-1999-1357 can allow remote attackers to exploit cross-site scripting vulnerabilities in CGI programs.

5

Is CVE-1999-1357 present in Netscape Communicator 4.8?

No, CVE-1999-1357 is not present in Netscape Communicator 4.8 or any later versions.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203