积极预防 及时发现
快速响应 力保恢复
BEA WebLogic 5.1.0的默认配置可导致远程攻击者通过请求一个以/file/开始的URL...
发布时间:2002-05-20 信息来源:管理员

CNCVE编号:CNCVE-20000500 CVE编号:CVE-2000-0500 安全级别:中 漏洞中文描述: BEA WebLogic 5.1.0的默认配置可导致远程攻击者通过请求一个以/file/开始的URL来查看程序的源代码,这会使得默认servlet显示没有进一步处理的文件。 漏洞英文描述: The default configuration of BEA WebLogic 5.1.0 allows a remote attacker to view source code of programs by requesting a URL beginning with /file/, which causes the default servlet to display the file without further processing. 漏洞参考: 系统类型:其他 漏洞类型:其他