CVE-2000-0236: Medium severity Netscape Enterprise Server vulnerability
Netscape Enterprise Server with Directory Indexing enabled allows remote attackers to list server directories via web publishing tags such as ?wp-ver-info and ?wp-cs-dump.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Disable Directory Indexing in the server configuration to prevent remote directory listings triggered by web publishing tags (e.g. ?wp-ver-info, ?wp-cs-dump).
Netscape Enterprise Server Directory Indexing = disabled - Configuration
Disable or remove the web publishing tags/features such as ?wp-ver-info and ?wp-cs-dump so they cannot be used to enumerate server directories.
Netscape Enterprise Server (Web Publishing) web publishing tags = disable ?wp-ver-info and ?wp-cs-dump
Event History
Frequently Asked Questions
What is the severity of CVE-2000-0236?
CVE-2000-0236 is considered a moderate severity vulnerability due to its ability to expose directory listings.
How do I fix CVE-2000-0236?
To fix CVE-2000-0236, disable directory indexing on the Netscape Enterprise Server.
What systems are affected by CVE-2000-0236?
CVE-2000-0236 affects Netscape Enterprise Server versions 3.0, 3.5.1, and 3.6.
What types of attacks can exploit CVE-2000-0236?
CVE-2000-0236 can be exploited by remote attackers to list server directories using specific web publishing tags.
Is CVE-2000-0236 still a concern today?
While CVE-2000-0236 is an older vulnerability, it remains a concern for systems still running the affected versions of Netscape Enterprise Server.