BroadVision One-To-One Enterprise allows remote attackers to determine the physical path of server files by requesting a .JSP file name that does not exist.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/5661 | vdb entry |
http://archives.neohapsis.com/archives/bugtraq/2000-12/0074.html | mailing list exploit vendor advisory |