Vulnerability Name: | CCN-6058 | ||||||
Published: | 2001-02-02 | ||||||
Updated: | 2001-02-02 | ||||||
Summary: | Netscape Enterprise Server could allow a remote attacker to search for Web index content, due to a vulnerability in the Netscape Web Publisher. Netscape Web Publisher is a Java Web-based program installed by default in the Netscape Enterprise Server. The program is designed to allow remote file uploads, downloads, and changes to the Web server. If the /publisher directory and the index are public, and if Netscape Enterprise Server is using certificate-based authentication, a remote attacker can use a proxy to accept the certificate and use Netscape Web Publisher. An attacker could use this vulnerability to search for Web index content and view or download private files on the Web server. | ||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||
CVSS v2 Severity: | 5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
| ||||||
Vulnerability Consequences: | Obtain Information | ||||||
References: | Source: CCN Type: BugTraq Mailing List, Fri Feb 02 2001 - 12:57:34 CST Netscape E.S. Web Publisher ACL Vulnerabilities Source: XF Type: UNKNOWN netscape-webpublisher-acl-permissions(6058) | ||||||
Vulnerable Configuration: | Configuration CCN 1:![]() | ||||||
BACK |