IBM WebSphere源代码暴露漏洞

自家种植的苹果

自家种植的苹果

2016-02-19 15:12

生活已是百般艰难,为何不努力一点。下面图老师就给大家分享IBM WebSphere源代码暴露漏洞,希望可以让热爱学习的朋友们体会到设计的小小的乐趣。
bugtraq id 1500
  class Access Validation Error
  cve GENERIC-MAP-NOMATCH
  remote Yes
  local Yes
  published July 24, 2000
  updated July 24, 2000
  vulnerable IBM Websphere Application Server 3.0.21
  - Sun Solaris 8.0
  - Microsoft Windows NT 4.0
  - Linux kernel 2.3.x
  - IBM AIX 4.3
  IBM Websphere Application Server 3.0
  - Sun Solaris 8.0
  - Novell Netware 5.0
  - Microsoft Windows NT 4.0
  - Linux kernel 2.3.x
  - IBM AIX 4.3
  IBM Websphere Application Server 2.0
  - Sun Solaris 8.0
  - Novell Netware 5.0
  - Microsoft Windows NT 4.0
  - Linux kernel 2.3.x
  - IBM AIX 4.3
  
  Certain versions of the IBM WebSphere application server ship with a vulnerability which allows malicious users to view the source of any document which resides in the web document root directory.
  
  This is possible via a flaw which allows a default servlet (different servlets are used to parse different types of content, JHTML, HTMl, JSP, etc.) This default servlet will display the document/page without parsing/compiling it hence allowing the code to be viewed by the end user.
  
  The Foundstone, Inc. advisory which covered this problem detailed the following method of verifying the vulnerability - full text of this advisory is available in the 'Credit' section of this entry:
  
  "It is easy to verify this vulnerability for a given system. Prefixing the path to web pages with "/servlet/file/" in the URL causes the file to be displayed without being
  parsed or compiled. For example if the URL for a file "login.jsp" is:
  
  http://site.running.websphere/login.jsp
  
  then accessing
  
  http://site.running.websphere/servlet/file/login.jsp
  
  would cause the unparsed contents of the file to show up in the web browser."
展开更多 50%)
分享

猜你喜欢

IBM WebSphere源代码暴露漏洞

Web开发
IBM WebSphere源代码暴露漏洞

IBM WebSphere Application Server 3.0.2 存在暴露源代码漏洞

Java JAVA基础
IBM WebSphere Application Server 3.0.2 存在暴露源代码漏洞

s8lol主宰符文怎么配

英雄联盟 网络游戏
s8lol主宰符文怎么配

BEA WebLogic 暴露源代码漏洞

Java JAVA基础
BEA WebLogic 暴露源代码漏洞

Resin 1.2 重要源代码暴露漏洞

Java JAVA基础
Resin 1.2 重要源代码暴露漏洞

lol偷钱流符文搭配推荐

英雄联盟 网络游戏
lol偷钱流符文搭配推荐

IBM WebSphere Application Server 暴露JSP文件内容

Java JAVA基础
IBM WebSphere Application Server 暴露JSP文件内容

多中WEB服务器的通用JSp源代码暴露漏洞

Java JAVA基础
多中WEB服务器的通用JSp源代码暴露漏洞

lolAD刺客新符文搭配推荐

英雄联盟
lolAD刺客新符文搭配推荐

jsp 实现在线人数统计

jsp 实现在线人数统计

Word 2007技巧:在文档中压缩图片

Word 2007技巧:在文档中压缩图片
下拉加载更多内容 ↓