CNCVE编号:CNCVE-20010399 CVE编号:CAN-2001-0399 安全级别:中 漏洞中文描述: Caucho Resin 1.3b1及其早期版本允许远程攻击者通过一个在WEB-INF区分符前的.jsp嵌入一个HTTP请求中来阅读源代码。 漏洞英文描述: Caucho Resin 1.3b1 and earlier allows remote attackers to read source code for Javabean files by inserting a .jsp before the WEB-INF specifier in an HTTP request. 漏洞参考: BUGTRAQ:20010403 CHINANSL Security Advisory(CSA-200111) URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98633597813833&w=2 BID:2533 URL:http://www.securityfocus.com/bid/2533 系统类型: Unix/Linux Win95/98/ME Win2000/NT 漏洞类型:输入有效性检查错误