CVE-2002-1042
Netscape Enterprise Server and iPlanet Web Server - Directory Traversal via NS-query-pat Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2002-1042. PoCs published by Qualys Corporation.
AI-analyzed exploit summary The exploit demonstrates a directory traversal vulnerability in iPlanet Web Server's search engine, allowing remote attackers to read arbitrary files on Windows systems. The provided GET request exploits the vulnerability to access the boot.ini file.
Description
Directory traversal vulnerability in search engine for iPlanet web server 6.0 SP2 and 4.1 SP9, and Netscape Enterprise Server 3.6, when running on Windows platforms, allows remote attackers to read arbitrary files via ..\ (dot-dot backslash) sequences in the NS-query-pat parameter.
Exploits (1)
The exploit demonstrates a directory traversal vulnerability in iPlanet Web Server's search engine, allowing remote attackers to read arbitrary files on Windows systems. The provided GET request exploits the vulnerability to access the boot.ini file.