积极预防 及时发现
快速响应 力保恢复
Allaire JRun 3.0允许远程攻击者通过包含“.”的畸形URL来列出WEB-INF目录的内...
发布时间:2001-05-03 信息来源:管理员

CNCVE编号:CNCVE-20010179 CVE编号:CVE-2001-0179 安全级别:中 漏洞中文描述: Allaire JRun 3.0允许远程攻击者通过包含“.”的畸形URL来列出WEB-INF目录的内容和WEB-INF目录中的web.xml文件。 漏洞英文描述: Allaire JRun 3.0 allows remote attackers to list contents of the WEB-INF directory, and the web.xml file in the WEB-INF directory, via a malformed URL that contains a "." 漏洞参考: XF:jrun-webinf-file-retrieval ALLAIRE:ASB01-02 系统类型: Unix/Linux Win95/98/ME Win2000/NT 漏洞类型:权限有效性检查错误