Allaire JRun JSP Source Disclosure...

- AV AC AU C I A
发布: 2001-12-06
修订: 2025-04-13

Allaire JRun is a web application development suite with JSP and Java Servlets. It is possible for a remote attacker to disclose JSP source code by making a specially crafted web request containing HTML encoded characters or a request which is appended by a null character(%00). This issue can be exploited with the following examples: http://target/directory/jsp/myjsp%00 http://target/directory/jsp/myjs%2570 This is also a known issue when Microsoft IIS is used as a connector for serving JSP files.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息