Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.12123
Category:Web Servers
Title:Apache Tomcat source.jsp Malformed Request Information Disclosure Vulnerability - Active Check
Summary:The source.jsp file, distributed with Apache Tomcat server, will; disclose information when passed a malformed request.
Description:Summary:
The source.jsp file, distributed with Apache Tomcat server, will
disclose information when passed a malformed request.

Vulnerability Impact:
As a result, information such as the web root path and directory
listings could be obtained.

Examples:

http://example.com/examples/jsp/source.jsp?? - reveals the web root

http://example.com/examples/jsp/source.jsp?/jsp/ - reveals the contents of the jsp directory

Affected Software/OS:
Apache Tomcat versions 3.2.3 and 3.2.4 are known to be
affected. Other newer or older versions might be affected as well.

Solution:
Remove the default files from the web server.

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:N/A:N

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2002-2007
BugTraq ID: 4876
http://www.securityfocus.com/bid/4876
BugTraq ID: 4877
http://www.securityfocus.com/bid/4877
BugTraq ID: 4878
http://www.securityfocus.com/bid/4878
Bugtraq: 20020529 Vulnerability in Apache Tomcat v3.23 & v3.24 (Google Search)
http://cert.uni-stuttgart.de/archive/bugtraq/2002/05/msg00272.html
Bugtraq: 20020529 Vulnerability in Apache Tomcat v3.23 & v3.24 (part 2) (Google Search)
http://cert.uni-stuttgart.de/archive/bugtraq/2002/05/msg00275.html
CERT/CC vulnerability note: VU#116963
http://www.kb.cert.org/vuls/id/116963
http://www.procheckup.com/security_info/vuln_pr0205.html
http://www.procheckup.com/security_info/vuln_pr0206.html
http://www.procheckup.com/security_info/vuln_pr0207.html
http://www.iss.net/security_center/static/9208.php
CopyrightCopyright (C) 2004 David Kyger

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.