• 企业400电话
  • 微网小程序
  • AI电话机器人
  • 电商代运营
  • 全 部 栏 目

    企业400电话 网络优化推广 AI电话机器人 呼叫中心 网站建设 商标✡知产 微网小程序 电商运营 彩铃•短信 增值拓展业务
    IBM WebSphere源代码暴露漏洞
    bugtraq id 1500
    class Access Validation Error
    cve GENERIC-MAP-NOMATCH
    remote Yes
    local Yes
    published July 24, 2000
    updated July 24, 2000
    vulnerable IBM Websphere Application Server 3.0.21
    - Sun Solaris 8.0
    - Microsoft Windows NT 4.0
    - Linux kernel 2.3.x
    - IBM AIX 4.3
    IBM Websphere Application Server 3.0
    - Sun Solaris 8.0
    - Novell Netware 5.0
    - Microsoft Windows NT 4.0
    - Linux kernel 2.3.x
    - IBM AIX 4.3
    IBM Websphere Application Server 2.0
    - Sun Solaris 8.0
    - Novell Netware 5.0
    - Microsoft Windows NT 4.0
    - Linux kernel 2.3.x
    - IBM AIX 4.3

    Certain versions of the IBM WebSphere application server ship with a vulnerability which allows malicious users to view the source of any document which resides in the web document root directory.

    This is possible via a flaw which allows a default servlet (different servlets are used to parse different types of content, JHTML, HTMl, JSP, etc.) This default servlet will display the document/page without parsing/compiling it hence allowing the code to be viewed by the end user.

    The Foundstone, Inc. advisory which covered this problem detailed the following method of verifying the vulnerability - full text of this advisory is available in the 'Credit' section of this entry:

    "It is easy to verify this vulnerability for a given system. Prefixing the path to web pages with "/servlet/file/" in the URL causes the file to be displayed without being
    parsed or compiled. For example if the URL for a file "login.jsp" is:

    http://site.running.websphere/login.jsp

    then accessing

    http://site.running.websphere/servlet/file/login.jsp

    would cause the unparsed contents of the file to show up in the web browser."
    上一篇:jsp计数器代码
    下一篇:Sun认为C#不会替代Java
  • 相关文章
  • 

    © 2016-2020 巨人网络通讯 版权所有

    《增值电信业务经营许可证》 苏ICP备15040257号-8

    IBM WebSphere源代码暴露漏洞 IBM,WebSphere,源代码,暴露,