Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 145615 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.12123
Kategorie:Web Servers
Titel:Apache Tomcat source.jsp Malformed Request Information Disclosure Vulnerability - Active Check
Zusammenfassung:The source.jsp file, distributed with Apache Tomcat server, will; disclose information when passed a malformed request.
Beschreibung:Summary:
The source.jsp file, distributed with Apache Tomcat server, will
disclose information when passed a malformed request.

Vulnerability Impact:
As a result, information such as the web root path and directory
listings could be obtained.

Examples:

http://example.com/examples/jsp/source.jsp?? - reveals the web root

http://example.com/examples/jsp/source.jsp?/jsp/ - reveals the contents of the jsp directory

Affected Software/OS:
Apache Tomcat versions 3.2.3 and 3.2.4 are known to be
affected. Other newer or older versions might be affected as well.

Solution:
Remove the default files from the web server.

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:N/A:N

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2002-2007
BugTraq ID: 4876
http://www.securityfocus.com/bid/4876
BugTraq ID: 4877
http://www.securityfocus.com/bid/4877
BugTraq ID: 4878
http://www.securityfocus.com/bid/4878
Bugtraq: 20020529 Vulnerability in Apache Tomcat v3.23 & v3.24 (Google Search)
http://cert.uni-stuttgart.de/archive/bugtraq/2002/05/msg00272.html
Bugtraq: 20020529 Vulnerability in Apache Tomcat v3.23 & v3.24 (part 2) (Google Search)
http://cert.uni-stuttgart.de/archive/bugtraq/2002/05/msg00275.html
CERT/CC vulnerability note: VU#116963
http://www.kb.cert.org/vuls/id/116963
http://www.procheckup.com/security_info/vuln_pr0205.html
http://www.procheckup.com/security_info/vuln_pr0206.html
http://www.procheckup.com/security_info/vuln_pr0207.html
http://www.iss.net/security_center/static/9208.php
CopyrightCopyright (C) 2004 David Kyger

Dies ist nur einer von 145615 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.