CVE-1999-1130 EXPLOIT
5.0
MEDIUM · CVSS 2.0 · EPSS 3.1% (pctl 87)
Patch early
A public exploit exists.
Description
Default configuration of the search engine in Netscape Enterprise Server 3.5.1, and possibly other versions, allows remote attackers to read the source of JHTML files by specifying a search command using the HTML-tocrec-demo1.pat pattern file.
Scoring
| CVSS | 5.0 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
| EPSS | 3.06% — more likely to be exploited than 87% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 1999-07-30 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| netscape | enterprise server |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Netscape Enterprise Server 3.51/3.6 - JHTML View Source | 1999-07-30 |
References
→ the Explorer · watch your stack · NVD