CVE-2000-0236

Netscape Enterprise Server - Info Disclosure

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2000-0236. PoCs published by Gabriel Maggiotti.

AI-analyzed exploit summary This exploit demonstrates a directory traversal vulnerability in Netscape Enterprise Server 3.x by sending a crafted HTTP request to enable directory listing. The code constructs a malicious GET request and sends it to the target server, then prints the response.

Description

Netscape Enterprise Server with Directory Indexing enabled allows remote attackers to list server directories via web publishing tags such as ?wp-ver-info and ?wp-cs-dump.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Gabriel Maggiotti · cremotemultiple
https://www.exploit-db.com/exploits/19814

This exploit demonstrates a directory traversal vulnerability in Netscape Enterprise Server 3.x by sending a crafted HTTP request to enable directory listing. The code constructs a malicious GET request and sends it to the target server, then prints the response.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Netscape Enterprise Server 3.x
No auth needed
Prerequisites: Network access to the target server · Netscape Enterprise Server 3.x with directory indexing enabled
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/1063
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/templates/archive.pike?list=1&msg=38D2173D.24E39DD0%40relaygroup.com

Scores

EPSS 0.0592
EPSS Percentile 92.3%

Details

Status published
Products (3)
netscape/enterprise_server 3.0
netscape/enterprise_server 3.5.1
netscape/enterprise_server 3.6
Published Mar 17, 2000
Tracked Since Feb 18, 2026