文章导航PC6首页软件下载单机游戏安卓资源苹果资源

pc软件新闻网络操作系统办公工具编程服务器软件评测

安卓新闻资讯应用教程刷机教程安卓游戏攻略tv资讯深度阅读综合安卓评测

苹果ios资讯苹果手机越狱备份教程美化教程ios软件教程mac教程

单机游戏角色扮演即时战略动作射击棋牌游戏体育竞技模拟经营其它游戏游戏工具

网游cf活动dnf活动lol周免英雄lol礼包

手游最新动态手游评测手游活动新游预告手游问答

您的位置:首页网页设计JSP文摘 → apache tomcat的snoop servlet漏洞 

apache tomcat的snoop servlet漏洞 

时间:2004/11/7 3:40:00来源:本站整理作者:蓝点我要评论(0)

bugtraq id 1500

class Access Validation Error

cve GENERIC-MAP-NOMATCH

remote Yes

local Yes

published July 24, 2000

updated July 24, 2000

vulnerable IBM Websphere Application Server 3.0.21

- Sun Solaris 8.0

- Microsoft Windows NT 4.0

- Linux kernel 2.3.x

- IBM AIX 4.3

IBM Websphere Application Server 3.0

- Sun Solaris 8.0

- Novell Netware 5.0

- Microsoft Windows NT 4.0

- Linux kernel 2.3.x

- IBM AIX 4.3

IBM Websphere Application Server 2.0

- Sun Solaris 8.0

- Novell Netware 5.0

- Microsoft Windows NT 4.0

- Linux kernel 2.3.x

- IBM AIX 4.3



Certain versions of the IBM WebSphere application server ship with a vulnerability which allows malicious users to view the source of any document which resides in the web document root directory.



This is possible via a flaw which allows a default servlet (different servlets are used to parse different types of content, JHTML, HTMl, JSP, etc.) This default servlet will display the document/page without parsing/compiling it hence allowing the code to be viewed by the end user.



The Foundstone, Inc. advisory which covered this problem detailed the following method of verifying the vulnerability - full text of this advisory is available in the 'Credit' section of this entry:



"It is easy to verify this vulnerability for a given system. Prefixing the path to web pages with "/servlet/file/" in the URL causes the file to be displayed without being

parsed or compiled. For example if the URL for a file "login.jsp" is:



http://site.running.websphere/login.jsp



then accessing



http://site.running.websphere/servlet/file/login.jsp



would cause the unparsed contents of the file to show up in the web browser."




相关阅读 Windows错误代码大全 Windows错误代码查询激活windows有什么用Mac QQ和Windows QQ聊天记录怎么合并 Mac QQ和Windows QQ聊天记录Windows 10自动更新怎么关闭 如何关闭Windows 10自动更新windows 10 rs4快速预览版17017下载错误问题Win10秋季创意者更新16291更新了什么 win10 16291更新内容windows10秋季创意者更新时间 windows10秋季创意者更新内容kb3150513补丁更新了什么 Windows 10补丁kb3150513是什么

文章评论
发表评论

热门文章 没有查询到任何记录。

最新文章 没有查询到任何记录。 JSP内置对象详解告诉大家什么是JSPJava 7的主要变化一个开发人员眼中的JSP技术下

人气排行 C++生成随机数—生成任意范围内的等概率随机apache tomcat的snoop servlet漏洞 IBM WebSphere Application Server 3.0.2 存BEA WebLogic 暴露源代码漏洞c++中new和delete的使用方法基于JSP的动态网站开发技术Java线程的深入探讨JSP多种web应用服务器导致JSP源码泄漏漏洞