CVE-2002-1042: Medium severity Netscape Enterprise server vulnerability

Published Aug 31, 2002
·
Updated

Directory traversal vulnerability in search engine for iPlanet web server 6.0 SP2 and 4.1 SP9, and Netscape Enterprise Server 3.6, when running on Windows platforms, allows remote attackers to read arbitrary files via ..\ (dot-dot backslash) sequences in the NS-query-pat parameter.

Affected Software

26 affected components
Netscape Enterprise server=3.6
Sun iPlanet Web Server=4.1
Sun iPlanet Web Server=4.1-sp1
Sun iPlanet Web Server=4.1-sp1
Sun iPlanet Web Server=4.1-sp10
Sun iPlanet Web Server=4.1-sp10
Sun iPlanet Web Server=4.1-sp2
Sun iPlanet Web Server=4.1-sp2
Sun iPlanet Web Server=4.1-sp3
Sun iPlanet Web Server=4.1-sp3
Sun iPlanet Web Server=4.1-sp4
Sun iPlanet Web Server=4.1-sp4
Sun iPlanet Web Server=4.1-sp5
Sun iPlanet Web Server=4.1-sp5
Sun iPlanet Web Server=4.1-sp6
Sun iPlanet Web Server=4.1-sp6
Sun iPlanet Web Server=4.1-sp7
Sun iPlanet Web Server=4.1-sp7
Sun iPlanet Web Server=4.1-sp8
Sun iPlanet Web Server=4.1-sp8
Sun iPlanet Web Server=4.1-sp9
Sun iPlanet Web Server=4.1-sp9
Sun ONE Application Server=6.0
Sun ONE Application Server=6.0-sp1
Sun ONE Application Server=6.0-sp2
Sun ONE Web Server=6.0-sp3

Event History

Aug 31, 2002
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2002-1042?

CVE-2002-1042 is considered a medium severity vulnerability due to its potential to allow unauthorized file access.

2

How do I fix CVE-2002-1042?

To fix CVE-2002-1042, apply the latest service pack or patch provided by the vendor for the affected software.

3

What software is affected by CVE-2002-1042?

CVE-2002-1042 affects iPlanet Web Server and Sun ONE Web Server on specific versions running on Windows platforms.

4

What type of attack does CVE-2002-1042 facilitate?

CVE-2002-1042 facilitates directory traversal attacks, allowing remote attackers to read arbitrary server files.

5

When was CVE-2002-1042 disclosed?

CVE-2002-1042 was disclosed in July 2002, highlighting vulnerabilities in early web server software.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203