CVE漏洞中文网

0DayBank一个专门收集整理全球互联网漏洞的公开发布网站
  1. 首页
  2. CVE
  3. 正文

BEA Systems WebLogic Server JSP Source Code Disclosure Vulnerability

2016年9月26日 1245点热度 0人点赞 0条评论

漏洞类别:Web server漏洞等级:

漏洞信息

BEA Systems WebLogic Server is an Enterprise-level Web and wireless application server.

If the letters in a JSP or a JHTML file extension are changed from lower case to upper case in a URL, such as .jsp to .JSP, then the server does not recognize the file extension and sends the file normally.

漏洞危害

As a result of this vulnerability being exploited, unauthorized remote users can access the source code for those specific files.

解决方案

As a workaround, you can add handlers of all possible configurations, including upper and lower case combinations, for the specific file extensions.

BEA Systems released a patch (caseSensitiveNTFix318.zip) for Version 3.1.8, which is available for download from the following FTP site:
ftp://ftpna.beasys.com/pub/releases/318/caseSensitiveNTFix318.ziphref="

0day

标签: 暂无
最后更新:2016年10月22日

小助手

这个人很懒,什么都没留下

点赞
< 上一篇
下一篇 >

文章评论

您需要 登录 之后才可以评论

COPYRIGHT © 2024 www.pdr.cn CVE漏洞中文网. ALL RIGHTS RESERVED.

鲁ICP备2022031030号

联系邮箱:wpbgssyubnmsxxxkkk@proton.me