IBM WebSphere plugin for Netscape Enterprise server allows remote attackers to read source code for JSP files via an HTTP request that contains a host header that references a host that is not in WebSphere's host aliases list, which will bypass WebSphere processing.
Link | Tags |
---|---|
http://archives.neohapsis.com/archives/bugtraq/2001-01/0446.html | mailing list exploit patch vendor advisory |