![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
CVE ID: | CVE-2006-0819 |
Description: | Dwarf HTTP Server 1.3.2 allows remote attackers to obtain the source code of JSP files via (1) dot, (2) space, (3) slash, or (4) NULL characters in the filename extension of an HTTP request. |
Test IDs: | None available |
Cross References: |
Common Vulnerability Exposure (CVE) ID: CVE-2006-0819 BugTraq ID: 17123 http://www.securityfocus.com/bid/17123 Bugtraq: 20060313 Secunia Research: Dwarf HTTP Server Source Disclosure andCross-Site Scripting (Google Search) http://www.securityfocus.com/archive/1/427478/100/0/threaded http://secunia.com/secunia_research/2006-13/advisory http://www.osvdb.org/23836 http://securitytracker.com/id?1015779 http://secunia.com/advisories/18962 http://securityreason.com/securityalert/576 http://www.vupen.com/english/advisories/2006/0937 XForce ISS Database: dwarfhttp-extension-information-disclosure(25178) https://exchange.xforce.ibmcloud.com/vulnerabilities/25178 |