Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.11604
Category:CGI abuses
Title:BEA WebLogic Scripts Server scripts Source Disclosure (3)
Summary:NOSUMMARY
Description:Description:

BEA WebLogic may be tricked into revealing the source code of JSP scripts
by prefixing the path to the .jsp files by /*.shtml/


Solution: Use the official patch available at http://www.bea.com
or upgrade to a version newer than 5.1

Risk factor : Medium

Cross-Ref: BugTraq ID: 1517
Common Vulnerability Exposure (CVE) ID: CVE-2000-0683
http://www.securityfocus.com/bid/1517
Bugtraq: 20000728 BEA's WebLogic force handlers show code vulnerability (Google Search)
http://archives.neohapsis.com/archives/bugtraq/2000-07/0410.html
http://www.osvdb.org/1480
CopyrightThis script is (C) 2003 Renaud Deraison

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.