国产探花免费观看_亚洲丰满少妇自慰呻吟_97日韩有码在线_资源在线日韩欧美_一区二区精品毛片,辰东完美世界有声小说,欢乐颂第一季,yy玄幻小说排行榜完本

首頁 > 編程 > JSP > 正文

多中WEB服務器的通用JSp源代碼暴露漏洞

2019-11-18 21:49:15
字體:
來源:轉載
供稿:網友
bugtraq id 1328
class Design Error
cve CVE-2000-0499
remote Yes
local Yes
published June 08, 2000
updated November 10, 2000
vulnerable BEA Systems Weblogic 4.5.1
- Microsoft Windows NT 4.0
BEA Systems Weblogic 4.0.4
- Microsoft Windows NT 4.0
BEA Systems Weblogic 3.1.8
- Microsoft Windows NT 4.0
IBM Websphere application Server 3.0.21
- Sun Solaris 8.0
- Microsoft Windows NT 4.0
- linux kernel 2.3.x
- IBM AIX 4.3
Unify eWave ServletExec 3.0
- Sun Solaris 8.0
- Microsoft Windows 98
- Microsoft Windows NT 4.0
- Microsoft Windows NT 2000
- Linux kernel 2.3.x
- IBM AIX 4.3.2
- HP HP-UX 11.4



Many webservers are case-sensitive, but do not have all possible combinations of cases in mapped extensions mapped PRoperly.

By changing the letters in a jsp or a JHTML file extension from lower case to upper case (eg: .jsp or .jhtml becomes .JSP or .JHTML) in a URL the server does not recognize the file extension and sends the file normally. In that manner, a user is able to access the source code to those specific files.




發表評論 共有條評論
用戶名: 密碼:
驗證碼: 匿名發表
主站蜘蛛池模板: 长海县| 耒阳市| 乌鲁木齐市| 六安市| 池州市| 新津县| 高州市| 鸡东县| 原阳县| 普格县| 礼泉县| 师宗县| 吴旗县| 桑日县| 静海县| 本溪市| 蓝田县| 灵山县| 蓬莱市| 敦化市| 建瓯市| 大埔区| 庆安县| 册亨县| 东乌珠穆沁旗| 富阳市| 思南县| 昔阳县| 浏阳市| 日喀则市| 多伦县| 荣成市| 红安县| 南澳县| 夏津县| 峨山| 屏山县| 高密市| 平昌县| 中西区| 汾阳市|