Weblogic SSIServlet Show Code...

- AV AC AU C I A
发布: 2000-07-31
修订: 2025-04-13

Certain versions of BEA Systems Weblogic server ship with a vulnerability which allows malicious users to view the source of .jsp and .jhtml pages which reside in the web document root directory. This is possible due to a mistake in the provided weblogic.properties configuration which manifests itself if a user sends a request prefixed with /*.shtml/ . This will result in the SSIServlet (Server Side Include Servlet) being forced to display documents in the unparsed (raw precompiled) formats.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息