COMMAND
Netscape Enterprise 3.5.1
SYSTEMS AFFECTED
Win NT, Solaris
PROBLEM
Someone on NTSEC posted following one. In testing Netscape
Enterprise 3.5.1 for the /?PageServices query appeared to be
vulnerable. The Page Services function is a menu item under View
in Netscape Navigator 4.xx and Communicator. All one has to do is
load up a Web page, go to View on the menu bar and see it Page
Services is activated. If it is, select it and you'll get back a
directory listing of the Web server docs root. If there are
subdirectories in this root, you can see a listing of all the
files in these as well. /?PageServices query, only the Netscape
Enterprise 3.5.1 server running on NT produce a directory listing
of the docs root.
SOLUTION
Just turn off direcory indexing on the affected servers. Then
you just get a "Server Error" message