Sun ONE Application Server 7.0 for Windows 2000/XP allows remote attackers to obtain JSP source code via a request that uses the uppercase ".JSP" extension instead of the lowercase .jsp extension.
The product does not properly account for differences in case sensitivity when accessing or determining the properties of a resource, leading to inconsistent results.
Link | Tags |
---|---|
http://www.spidynamics.com/sunone_alert.html | broken link |
http://www.iss.net/security_center/static/12093.php | patch vendor advisory broken link vdb entry |
http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert%2F55221&zone_32=category%3Asecurity | patch vendor advisory broken link |
http://www.ciac.org/ciac/bulletins/n-103.shtml | patch vendor advisory broken link government resource third party advisory |
http://marc.info/?l=bugtraq&m=105409846029475&w=2 | exploit mailing list |
http://www.securityfocus.com/bid/7709 | patch vdb entry exploit vendor advisory broken link third party advisory |
http://sunsolve.sun.com/search/document.do?assetkey=1-77-1000610.1-1 | vendor advisory broken link |