Junglewise Threat Intelligence

CVE-1999-0239: Netscape FastTrack Web Server directory listing via case-sensitive GET bypass

CVE-1999-0239 · Severity: high · CVSS 7.5 · Published 1998-01-01

Vendors: Netscape.

Executive brief

Netscape FastTrack Web Server, a legacy software used for hosting websites, contains a flaw that allows unauthorized users to view the contents of directories on the server. By sending a specific command in lowercase instead of the expected uppercase, an attacker can bypass security restrictions to see a list of files. This could lead to the exposure of sensitive configuration files or internal data that was not intended for public viewing.

Technical details

A case-sensitivity vulnerability (CWE-178) exists in the Netscape FastTrack Web server's handling of HTTP methods. When a remote, unauthenticated attacker sends a request using the lowercase 'get' command instead of the RFC-compliant uppercase 'GET', the server fails to apply standard access controls or index file defaults, instead returning a directory listing of the requested path. This allows for information disclosure of server-side files and directory structures. The vulnerability is exploitable over the network without user interaction.

Affected products

  • Netscape FastTrack Web Server

Timeline

  • 1998-01-01: disclosed: Initial publication date

References