secunia-Blazix.txt...

- AV AC AU C I A
发布: 2006-04-01
修订: 2025-04-13

Secunia Research has discovered a vulnerability in Blazix, which can be exploited by malicious people to disclose potentially sensitive information. The vulnerability is caused due to a validation error of the filename extension supplied by the user in the URL. This can be exploited to retrieve the source code of JSP files from the server via specially crafted requests containing dot, space, and slash characters. Version 1.2.5 is affected.

0%
当前有1条漏洞利用/PoC
当前有0条受影响产品信息