vendor:
Enterprise Server
by:
David Litchfield
7.5
CVSS
HIGH
Full Text Disclosure
200
CWE
Product Name: Enterprise Server
Affected Version From: 3.51
Affected Version To: 3.51
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2002
Netscape Enterprise Server 3.51 Full Text Disclosure Vulnerability
Netscape Enterprise Server 3.51 and above includes a search engine by default. The results it generates can be tailored using various configuration files, and one of the options is whether or not the full text of a resultant page is displayed. This option is turned off by default. However, even with this setting in place, it is possible to construct a specific query that will return the full text of a JHTML page (active content, similar to an IIS .asp page) or other scripted files.
Mitigation:
Ensure that the full text of a resultant page is not displayed by setting the appropriate configuration options.