CVE-2000-0739

NAI Net Tools PKI Server 1.0 - Directory Traversal via HTTPS Request

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2000-0739. PoCs published by Juliano Rizzo.

AI-analyzed exploit summary The exploit describes a directory traversal vulnerability in Network Associates Net Tools PKI Server's Enrollment Web Server (strong.exe) on port 444, allowing unauthenticated remote attackers to read arbitrary files by traversing outside the web root directory.

Description

Directory traversal vulnerability in strong.exe program in NAI Net Tools PKI server 1.0 before HotFix 3 allows remote attackers to read arbitrary files via a .. (dot dot) attack in an HTTPS request to the enrollment server.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Juliano Rizzo · textremotewindows
https://www.exploit-db.com/exploits/20135

The exploit describes a directory traversal vulnerability in Network Associates Net Tools PKI Server's Enrollment Web Server (strong.exe) on port 444, allowing unauthenticated remote attackers to read arbitrary files by traversing outside the web root directory.

Classification
Writeup 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Network Associates Net Tools PKI Server (versions with strong.exe)
No auth needed
Prerequisites: Network access to TCP port 444 · Knowledge of target file paths
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/1489
Vendor Advisory mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2000-07/0473.html
Exploit, Patch, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/1537
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/5066

Scores

EPSS 0.0287
EPSS Percentile 85.0%

Details

Status published
Products (3)
network_associates/net_tools_pki_server 1.0
network_associates/net_tools_pki_server 1.0hotfix1
network_associates/net_tools_pki_server 1.0hotfix2
Published Oct 20, 2000
Tracked Since Feb 18, 2026