CNCVE编号:CNCVE-20010590 CVE编号:CAN-2001-0590 安全级别:中 漏洞中文描述: Apache Software Foundation Tomcat Servlet 3.2.2早期版本允许远程攻击者通过一个不以HTTP协议规范(如HTTP/1.0)结束的畸形URL请求来阅读任意“jsp”文件的源代码。 漏洞英文描述: Apache Software Foundation Tomcat Servlet prior to 3.2.2 allows a remote attacker to read the source code to arbitrary 'jsp' files via a malformed URL request which does not end with an HTTP protocol specification (i.e. HTTP/1.0) 漏洞参考: Reference: BUGTRAQ:20010403 Re: Tomcat may reveal script source code by trickery Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-04/0031.html 系统类型:其他 漏洞类型:输入有效性检查错误