Directory traversal vulnerability in source.jsp of Apache Tomcat before 3.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the argument to source.jsp.
Link | Tags |
---|---|
http://www.iss.net/security_center/static/4205.php | patch vendor advisory vdb entry |
http://marc.info/?l=bugtraq&m=95371672300045&w=2 | mailing list |