Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-1999-0174 โ€” Communicator vulnerability

4 documents4 sources
Severity
6.4MEDIUMNVD
EPSS
8.1%
top 7.86%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedFeb 1
Latest updateApr 30

Description

The view-source CGI program allows remote attackers to read arbitrary files via a .. (dot dot) attack.

CVSS vector

AV:N/AC:L/C:P/I:P/A:NExploitability: 10.0 | Impact: 4.9

Affected Packages1 packages

โ–ถNVDnetscape/communicator7 versions+6

๐Ÿ”ดVulnerability Details

2
GHSA
GHSA-mfjc-659f-pj9j: The view-source CGI program allows remote attackers to read arbitrary files via aโ†—2022-04-30
โ–ถ
CVEList
CVE-1999-0174: The view-source CGI program allows remote attackers to read arbitrary files via aโ†—1999-09-29
โ–ถ

๐Ÿ’ฅExploits & PoCs

1
Exploit-DB
Skunkware 2.0 - view-source Directory Traversalโ†—1997-04-16
โ–ถ
CVE-1999-0174 โ€” Netscape Communicator vulnerability | cvebase