Unify eWave ServletExec allows a remote attacker to view source code of a JSP program by requesting a URL which provides the JSP extension in upper case.
The product does not properly account for differences in case sensitivity when accessing or determining the properties of a resource, leading to inconsistent results.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/1328 | vdb entry third party advisory broken link |
https://exchange.xforce.ibmcloud.com/vulnerabilities/4649 | vdb entry third party advisory |
http://archives.neohapsis.com/archives/ntbugtraq/2000-q2/0250.html | mailing list broken link vendor advisory |