IBM WebSphere server 3.0.2 allows a remote attacker to view source code of a JSP program by requesting a URL which provides the JSP extension in upper case.
The product does not properly account for differences in case sensitivity when accessing or determining the properties of a resource, leading to inconsistent results.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/1328 | vdb entry third party advisory broken link |
http://archives.neohapsis.com/archives/ntbugtraq/2000-q2/0263.html | mailing list broken link patch vendor advisory |
http://www-4.ibm.com/software/webservers/appserv/efix.html | product |