CVE-2001-0250: Medium severity Netscape Enterprise Server vulnerability
Published Apr 4, 2001
·Updated
The Web Publishing feature in Netscape Enterprise Server 4.x and earlier allows remote attackers to list arbitrary directories under the web server root via the INDEX command.
Affected Software
2 affected components
Netscape Enterprise Server=4.0
Netscape Enterprise Server=3.0
Remediation
Patch Available
Event History
Apr 4, 2001
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-0250?
CVE-2001-0250 is classified as a moderate severity vulnerability.
2
How do I fix CVE-2001-0250?
To fix CVE-2001-0250, disable the Web Publishing feature or upgrade to a secure version of Netscape Enterprise Server.
3
What are the potential risks associated with CVE-2001-0250?
The risks include unauthorized directory listing, which can expose sensitive files on the web server.
4
Which versions of Netscape Enterprise Server are affected by CVE-2001-0250?
CVE-2001-0250 affects Netscape Enterprise Server versions 3.0 and 4.0.
5
Who can exploit CVE-2001-0250?
Remote attackers with access to the web server can exploit CVE-2001-0250 to list arbitrary directories.