class Access Validation Error
cve GENERIC-MAP-NOMATCH
remote Yes
local Yes
published July 24, 2000
updated July 24, 2000
vulnerable IBM Websphere Application Server 3.0.21
- Sun " /> 黑人操亚洲女,九九自拍,亚洲图片欧美电影

四虎精品视频-四虎精品成人免费网站-四虎黄色网-四虎国产视频-国产免费91-国产蜜臀97一区二区三区

IBM WebSphere源代碼暴露漏洞

bugtraq id 1500
class Access Validation Error
cve GENERIC-MAP-NOMATCH
remote Yes
local Yes
published July 24, 2000
updated July 24, 2000
vulnerable IBM Websphere Application Server 3.0.21
- Sun Solaris 8.0
- Microsoft Windows NT 4.0
- Linux kernel 2.3.x
- IBM AIX 4.3
IBM Websphere Application Server 3.0
- Sun Solaris 8.0
- Novell NETware 5.0
- Microsoft Windows NT 4.0
- Linux kernel 2.3.x
- IBM AIX 4.3
IBM Websphere Application Server 2.0
- Sun Solaris 8.0
- Novell NETware 5.0
- Microsoft Windows NT 4.0
- Linux kernel 2.3.x
- IBM AIX 4.3

Certain versions of the IBM WebSphere application server ship with a vulnerability which allows malicious users to view the source of any document which resides in the web document root directory.

This is possible via a flaw which allows a default servlet (different servlets are used to parse different types of content, JHTML, HTMl, JSP, etc.) This default servlet will display the document/page without parsing/compiling it hence allowing the code to be viewed by the end user.

The Foundstone, Inc. advisory which covered this problem detailed the following method of verifying the vulnerability - full text of this advisory is available in the 'Credit' section of this entry:

"It is easy to verify this vulnerability for a given system. Prefixing the path to web pages with "/servlet/file/" in the URL causes the file to be displayed without being
parsed or compiled. For example if the URL for a file "login.jsp" is:

http://site.running.websphere/login.jsp

then accessing

http://site.running.websphere/servlet/file/login.jsp

would cause the unparsed contents of the file to show up in the web browser."

jsp技術IBM WebSphere源代碼暴露漏洞,轉載需保留來源!

鄭重聲明:本文版權歸原作者所有,轉載文章僅為傳播更多信息之目的,如作者信息標記有誤,請第一時間聯系我們修改或刪除,多謝。

主站蜘蛛池模板: 凤凰心计| 燃冬海报| 广播体操第七套视频完整版| 色蝴蝶| 我是传奇 电影| 极乐玩偶 (1981)| 假面骑士01| 加勒比海盗 电影| 绿门背后| av午夜| 电视剧暗夜与黎明剧情介绍| right here waiting中文版| 日本电影怪物| 试音文本| 最危险的游戏| 成人在线| 车震电影| 情人电影在线观看高清完整版泰剧| 肥皂泡节选阅读理解答案三年级| 周星驰原名| 音乐会电视剧免费观看完整版| 沉默的较量| 二年级上册期末真题卷| 王若涵| 余男狂怒| 十一码复式中奖表图片| 电影《大突围》完整版| 玻璃笼| 狗年电影| 天使和恶魔| 巨乳欧美| 《可爱的小鸟》阅读答案| 香港之夜免费观看| 雅多维尔围城战| 探究事物的本质的读后感想| 真实游戏完整在线观看免费高清| 春心荡漾第二季无删减| 贝子鸟叫声十三口| 李修蒙出生年月| 树屋上的童真| 谈判专家 电影|