CVE-2002-1042 EXPLOIT
5.0
MEDIUM · CVSS 2.0 · EPSS 3.9% (pctl 90)
Patch early
A public exploit exists.
Description
Directory traversal vulnerability in search engine for iPlanet web server 6.0 SP2 and 4.1 SP9, and Netscape Enterprise Server 3.6, when running on Windows platforms, allows remote attackers to read arbitrary files via ..\ (dot-dot backslash) sequences in the NS-query-pat parameter.
Scoring
| CVSS | 5.0 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
| EPSS | 3.85% — more likely to be exploited than 90% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2002-10-04 |
| Last modified | 2026-06-16 |
Affected (4)
| Vendor | Product |
|---|---|
| netscape | enterprise server |
| sun | iplanet web server |
| sun | one application server |
| sun | one web server |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | iPlanet Web Server 4.1 - Search Component File Disclosure | 2002-07-09 |
References
- http://archives.neohapsis.com/archives/bugtraq/2002-07/0085.html
- http://www.iss.net/security_center/static/9517.php
- http://www.securityfocus.com/bid/5191
- http://archives.neohapsis.com/archives/bugtraq/2002-07/0085.html
- http://www.iss.net/security_center/static/9517.php
- http://www.securityfocus.com/bid/5191
→ the Explorer · watch your stack · NVD