CNCVE编号:CNCVE-20000672 CVE编号:CVE-2000-0672 安全级别:中 漏洞中文描述: Jakarta Tomcat的默认配置不能限制对/admin context的访问,这导致远程攻击者可以通过直接调用administrative servlets为root目录增加context来读取任意命令。 漏洞英文描述: The default configuration of Jakarta Tomcat does not restrict access to the /admin context, which allows remote attackers to read arbitrary files by directly calling the administrative servlets to add a context for the root directory. 漏洞参考: 系统类型:其他 漏洞类型:其他