BEA Systems WebLogic Server...

- AV AC AU C I A
发布: 2001-03-26
修订: 2025-04-13

It is possible for an attacker to directory traverse the web folders of a BEA Systems WebLogic Server. Submitting a a URL with a known directory, and appended with specific ascii characters, will disclose the contents of the requested resource. The ASCII characters in question are %00, %2e, %2f and %5c. This vulnerability could allow the reading of files residing on the target system.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息