class Access Validation Error
cve GENERIC-MAP-NOMATCH
remote Yes
local Yes
published July 24, 2000
updated July 24, 2000
vulnerable IBM Websphere Application Server 3.0.21
- Sun " /> 亚洲 欧美 国产 在线 日韩,丝瓜涩涩屋黄瓜香蕉丝瓜,8x8x我要打机飞在线观看

天天躁日日躁狠狠躁AV麻豆-天天躁人人躁人人躁狂躁-天天澡夜夜澡人人澡-天天影视香色欲综合网-国产成人女人在线视频观看-国产成人女人视频在线观看

IBM WebSphere源代碼暴露漏洞

bugtraq id 1500
class Access Validation Error
cve GENERIC-MAP-NOMATCH
remote Yes
local Yes
published July 24, 2000
updated July 24, 2000
vulnerable IBM Websphere Application Server 3.0.21
- Sun Solaris 8.0
- Microsoft Windows NT 4.0
- Linux kernel 2.3.x
- IBM AIX 4.3
IBM Websphere Application Server 3.0
- Sun Solaris 8.0
- Novell NETware 5.0
- Microsoft Windows NT 4.0
- Linux kernel 2.3.x
- IBM AIX 4.3
IBM Websphere Application Server 2.0
- Sun Solaris 8.0
- Novell NETware 5.0
- Microsoft Windows NT 4.0
- Linux kernel 2.3.x
- IBM AIX 4.3

Certain versions of the IBM WebSphere application server ship with a vulnerability which allows malicious users to view the source of any document which resides in the web document root directory.

This is possible via a flaw which allows a default servlet (different servlets are used to parse different types of content, JHTML, HTMl, JSP, etc.) This default servlet will display the document/page without parsing/compiling it hence allowing the code to be viewed by the end user.

The Foundstone, Inc. advisory which covered this problem detailed the following method of verifying the vulnerability - full text of this advisory is available in the 'Credit' section of this entry:

"It is easy to verify this vulnerability for a given system. Prefixing the path to web pages with "/servlet/file/" in the URL causes the file to be displayed without being
parsed or compiled. For example if the URL for a file "login.jsp" is:

http://site.running.websphere/login.jsp

then accessing

http://site.running.websphere/servlet/file/login.jsp

would cause the unparsed contents of the file to show up in the web browser."

jsp技術(shù)IBM WebSphere源代碼暴露漏洞,轉(zhuǎn)載需保留來源!

鄭重聲明:本文版權(quán)歸原作者所有,轉(zhuǎn)載文章僅為傳播更多信息之目的,如作者信息標(biāo)記有誤,請(qǐng)第一時(shí)間聯(lián)系我們修改或刪除,多謝。

主站蜘蛛池模板: 51国产偷自视频在线视频播放 | 久久久免费观看 | 国产精品内射久久久久欢欢 | 和尚轮流澡到高潮H | 久久99热成人精品国产 | 2021年国产精品久久 | 伊人久久亚洲综合天堂 | chinese耄耋70老太性 | 野花韩国中文版免费观看 | 亚洲伊人久久大香线蕉综合图片 | 俄罗斯搜索引擎Yandex推广入口 | 青柠在线电影高清免费观看 | 疯狂做受XXXX高潮欧美日本 | 亚洲一卡二卡三卡四卡2021麻豆 | 免费看男人J放进女人J无遮掩 | 亚洲乱色视频在线观看 | 国产学生在线播放精品视频 | 韩国成人理伦片免费播放 | 国产精品久久久久久精品... | 国产黄A片在线观看永久免费麻豆 | 国产片MV在线观看 | 夜色爽爽爽久久精品日韩 | 野花韩国高清完整版在线观看5 | 麻豆国产自制在线观看 | 青青视频 在线 在线播放 | 秋霞网在线伦理免费 | 久久午夜一区二区 | 国产精品日本欧美一区二区 | 岛国电影网址 | 吉吉影音先锋av资源网 | 精品久久久亚洲精品中文字幕 | 黄色天堂在线 | 欧美麻豆一精品一AV一免费 | 日本高清免费一本在线观看 | 亚欧成人毛片一区二区三区四区 | 手机看片成人 | 欧美双拳极限扩张 | 果冻传媒色AV国产播放 | 少妇无码吹潮久久精品AV网站 | 亚洲精品资源网在线观看 | 116美女写真午夜电影z |