婷婷综合国产,91蜜桃婷婷狠狠久久综合9色 ,九九九九九精品,国产综合av

主頁 > 知識庫 > IBM WebSphere源代碼暴露漏洞

IBM WebSphere源代碼暴露漏洞

熱門標簽:四川電信外呼系統靠譜嗎 地圖標注創業項目入駐 電銷外呼系統 排行榜 地圖標注制作道路 外呼系統啥意思 長春回撥外呼系統廠家 廣州三五防封電銷卡 珠海銷售外呼系統運營商 山東智能云外呼管理系統
bugtraq id 1500
class Access Validation Error
cve GENERIC-MAP-NOMATCH
remote Yes
local Yes
published July 24, 2000
updated July 24, 2000
vulnerable IBM Websphere Application Server 3.0.21
- Sun Solaris 8.0
- Microsoft Windows NT 4.0
- Linux kernel 2.3.x
- IBM AIX 4.3
IBM Websphere Application Server 3.0
- Sun Solaris 8.0
- Novell Netware 5.0
- Microsoft Windows NT 4.0
- Linux kernel 2.3.x
- IBM AIX 4.3
IBM Websphere Application Server 2.0
- Sun Solaris 8.0
- Novell Netware 5.0
- Microsoft Windows NT 4.0
- Linux kernel 2.3.x
- IBM AIX 4.3

Certain versions of the IBM WebSphere application server ship with a vulnerability which allows malicious users to view the source of any document which resides in the web document root directory.

This is possible via a flaw which allows a default servlet (different servlets are used to parse different types of content, JHTML, HTMl, JSP, etc.) This default servlet will display the document/page without parsing/compiling it hence allowing the code to be viewed by the end user.

The Foundstone, Inc. advisory which covered this problem detailed the following method of verifying the vulnerability - full text of this advisory is available in the 'Credit' section of this entry:

"It is easy to verify this vulnerability for a given system. Prefixing the path to web pages with "/servlet/file/" in the URL causes the file to be displayed without being
parsed or compiled. For example if the URL for a file "login.jsp" is:

http://site.running.websphere/login.jsp

then accessing

http://site.running.websphere/servlet/file/login.jsp

would cause the unparsed contents of the file to show up in the web browser."

標簽:潮州 肇慶 紹興 北海 廣元 玉樹 保定 吳忠

巨人網絡通訊聲明:本文標題《IBM WebSphere源代碼暴露漏洞》,本文關鍵詞  IBM,WebSphere,源代碼,暴露,;如發現本文內容存在版權問題,煩請提供相關信息告之我們,我們將及時溝通與處理。本站內容系統采集于網絡,涉及言論、版權與本站無關。
  • 相關文章
  • 下面列出與本文章《IBM WebSphere源代碼暴露漏洞》相關的同類信息!
  • 本頁收集關于IBM WebSphere源代碼暴露漏洞的相關信息資訊供網民參考!
  • 推薦文章
    主站蜘蛛池模板: 永嘉县| 威信县| 肇州县| 云安县| 阿荣旗| 三门县| 罗江县| 宝清县| 崇礼县| 富顺县| 宣化县| 水富县| 舒兰市| 治多县| 繁峙县| 九寨沟县| 乡宁县| 应城市| 湄潭县| 含山县| 大关县| 玉溪市| 农安县| 锦州市| 霞浦县| 伊宁县| 弥勒县| 观塘区| 洛川县| 封开县| 仁化县| 福鼎市| 佛冈县| 苗栗县| 河北区| 辛集市| 固阳县| 辽阳市| 武乡县| 武山县| 中阳县|