CNCVE编号:CNCVE-20010446 CVE编号:CAN-2001-0446 安全级别:中 漏洞中文描述: 安装了Application Server 3.0.2的IBM WCS (WebSphere Commerce Suite) 4.0.1允许远程攻击者通过把一个/附加到被请求的URL来阅读.jsp文件的源代码。 漏洞英文描述: IBM WCS (WebSphere Commerce Suite) 4.0.1 with Application Server 3.0.2 allows remote attackers to read source code for .jsp files by appending a / to the requested URL. 漏洞参考: BUGTRAQ:20010328 CHINANSL Security Advisory(CSA-200107) URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98583082225053&w=2 系统类型:其他 漏洞类型:输入有效性检查错误