Netscape Enterprise Server with Web Publishing enabled allows remote attackers to list arbitrary directories via a GET request for the /publisher directory, which provides a Java applet that allows the attacker to browse the directories.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Enterprise_server | Netscape | 3.5 (including) | 3.5 (including) |
Enterprise_server | Netscape | 3.6 (including) | 3.6 (including) |