vendor:
Enterprise Server
by:
SecurityFocus
7.5
CVSS
HIGH
Directory Listing Disclosure
522
CWE
Product Name: Enterprise Server
Affected Version From: Netscape Enterprise Server 3.6
Affected Version To: Netscape Enterprise Server 4.1
Patch Exists: YES
Related CWE: CVE-2001-0206
CPE: a:netscape:enterprise_server
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows, Linux, Mac
2001
Netscape Enterprise Server with Web Publishing enabled will disclose the directory listing of the server to unauthenticated users who submit an INDEX request.
Netscape Enterprise Server with Web Publishing enabled will disclose the directory listing of the server to unauthenticated users who submit an INDEX request.
Mitigation:
Disable Web Publishing on the server.