Directory traversal vulnerability in search engine for iPlanet web server 6.0 SP2 and 4.1 SP9, and Netscape Enterprise Server 3.6, when running on Windows platforms, allows remote attackers to read arbitrary files via ..\ (dot-dot backslash) sequences in the NS-query-pat parameter.
References
Link | Resource |
---|---|
http://www.securityfocus.com/bid/5191 | Exploit Patch Vendor Advisory |
http://www.iss.net/security_center/static/9517.php | Patch Vendor Advisory |
http://archives.neohapsis.com/archives/bugtraq/2002-07/0085.html |
Configurations
Configuration 1 (hide)
|
Information
Published : 2002-10-03 21:00
Updated : 2008-09-05 13:29
NVD link : CVE-2002-1042
Mitre link : CVE-2002-1042
JSON object : View
CWE
Products Affected
sun
- iplanet_web_server
- one_application_server
- one_web_server
netscape
- enterprise_server