First published: Sat Mar 11 2000(Updated: )
Netscape Enterprise Server with Web Publishing enabled allows remote attackers to list arbitrary directories via a GET request for the /publisher directory, which provides a Java applet that allows the attacker to browse the directories.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Netscape Enterprise Server | =3.5 | |
Netscape Enterprise Server | =3.6 | |
=3.5 | ||
=3.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2000-0237 has a medium severity rating as it can allow unauthorized directory browsing.
To fix CVE-2000-0237, disable the Web Publishing feature in Netscape Enterprise Server.
CVE-2000-0237 affects Netscape Enterprise Server versions 3.5 and 3.6.
CVE-2000-0237 allows remote attackers to list arbitrary directories via a specially crafted GET request.
No, CVE-2000-0237 is specific to Netscape Enterprise Server software and not tied to a single platform.