国产探花免费观看_亚洲丰满少妇自慰呻吟_97日韩有码在线_资源在线日韩欧美_一区二区精品毛片,辰东完美世界有声小说,欢乐颂第一季,yy玄幻小说排行榜完本

首頁(yè) > 編程 > JSP > 正文

IBM WebSphere代碼漏洞處理措施

2024-09-05 00:18:06
字體:
來(lái)源:轉(zhuǎn)載
供稿:網(wǎng)友

  WebSphere是IBM的軟件平臺(tái),今天小編給大家分享一篇IBM WebSphere代碼漏洞處理措施,感興趣的朋友跟小編一起來(lái)了解一下吧!

  bugtraq id 1500

  class Access Validation Error

  cve GENERIC-MAP-NOMATCH

  remote Yes

  local Yes

  published July 24, 2000

  updated July 24, 2000

  vulnerable IBM Websphere Application Server 3.0.21

  - Sun Solaris 8.0

  - Microsoft Windows NT 4.0

  - Linux kernel 2.3.x

  - IBM AIX 4.3

  IBM Websphere Application Server 3.0

  - Sun Solaris 8.0

  - Novell Netware 5.0

  - Microsoft Windows NT 4.0

  - Linux kernel 2.3.x

  - IBM AIX 4.3

  IBM Websphere Application Server 2.0

  - Sun Solaris 8.0

  - Novell Netware 5.0

  - Microsoft Windows NT 4.0

  - Linux kernel 2.3.x

  - IBM AIX 4.3

  Certain versions of the IBM WebSphere application server ship with a vulnerability which allows malicious users to view the source of any document which resides in the web document root directory.

  This is possible via a flaw which allows a default servlet (different servlets are used to parse different types of content, JHTML, HTMl, JSP, etc.) This default servlet will display the document/page without parsing/compiling it hence allowing the code to be viewed by the end user.

  The Foundstone, Inc. advisory which covered this problem detailed the following method of verifying the vulnerability - full text of this advisory is available in the 'Credit' section of this entry:

  "It is easy to verify this vulnerability for a given system. Prefixing the path to web pages with "/servlet/file/" in the URL causes the file to be displayed without being

  parsed or compiled. For example if the URL for a file "login.jsp" is:

  http://site.running.websphere/login.jsp

  then accessing

  http://site.running.websphere/servlet/file/login.jsp

  would cause the unparsed contents of the file to show up in the web browser."

  以上就是IBM WebSphere代碼漏洞處理措施,想必都了解了吧,更多相關(guān)內(nèi)容請(qǐng)繼續(xù)關(guān)注錯(cuò)新技術(shù)頻道。

發(fā)表評(píng)論 共有條評(píng)論
用戶名: 密碼:
驗(yàn)證碼: 匿名發(fā)表
主站蜘蛛池模板: 宿州市| 武清区| 庄河市| 治多县| 两当县| 汉寿县| 留坝县| 太仆寺旗| 精河县| 凤冈县| 福海县| 教育| 富源县| 南江县| 新宁县| 马鞍山市| 义乌市| 西城区| 宜州市| 汾西县| 宽甸| 寿光市| 清水县| 大安市| 亚东县| 兖州市| 金堂县| 镇康县| 宜都市| 土默特右旗| 太和县| 普陀区| 阳高县| 深水埗区| 铁力市| 久治县| 大厂| 华宁县| 怀化市| 怀化市| 乌兰察布市|