||Home : Advisories : RESIN ServletExec JSP Source Disclosure Vulnerability|
||RESIN ServletExec JSP Source Disclosure Vulnerability
||23rd November 2000
Resin provides a fast servlet runner for Apache, allowing Apache to run servlets and JSP files.
But On Resin1.2(maybe Resin1.1 also) with Win32(Win2k Simplify Chinese version)Apache ,ServletExec will return the source code of JSP files when a HTTP request is appended with one of the following characters:
For example, the following URL will display the source of the specified JSP file:
Successful exploitation could lead to the disclosure of sensitive information contained within JSP pages.
I have reported this bug to the vendor,but they do nothing about it.
Share what I konw,Learn what I don't