peter bassill · operator
$ cve CVE-2002-1042 JSON

CVE-2002-1042 EXPLOIT

5.0
MEDIUM · CVSS 2.0 · EPSS 3.9% (pctl 90)

Patch early

A public exploit exists.

Description

Directory traversal vulnerability in search engine for iPlanet web server 6.0 SP2 and 4.1 SP9, and Netscape Enterprise Server 3.6, when running on Windows platforms, allows remote attackers to read arbitrary files via ..\ (dot-dot backslash) sequences in the NS-query-pat parameter.

Scoring

CVSS5.0 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS3.85% — more likely to be exploited than 90% of all CVEs
On CISA KEVno
Public exploityes
Published2002-10-04
Last modified2026-06-16

Affected (4)

VendorProduct
netscapeenterprise server
suniplanet web server
sunone application server
sunone web server

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD