OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: lovehacker (lovehacker263.NET)
Date: Sun Apr 01 2001 - 22:49:00 CDT

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    Topic:Tomcat 4.0-b2 for winnt/2000 show ".jsp"
    source Vulnerability.

    vulnerable:
    winnt/2000(maybe for other operating system also)
    + Tomcat 4.0-b2

    discussion:
    A security vulnerability has been found in Windows
    NT/2000 systems that have Tomcat 4.0-b2 installed.
    The
    vulnerability allows remote attackers to get ".jsp"
    source.

    exploits:
    http://target:8080/examples/snp/snoop%252ejsp

    solution:
    None

    Copyright 2000-2001 CHINANSL. All Rights
    Reserved. Terms of use.
    CHINANSL Security Team
    <lovehackerchinansl.com>
    CHINANSL INFORMATION TECHNOLOGY CO.,LTD
    (http://www.chinansl.com)