gnujsp 1.0.0 and 1.0.1 allows remote attackers to list directories, read source code of certain scripts, and bypass access restrictions by directly requesting the target file from the gnujsp servlet, which does not work around a limitation of JServ and does not process the requested file.
References
Configurations
Configuration 1 (hide)
|
History
20 Nov 2024, 23:38
Type | Values Removed | Values Added |
---|---|---|
References | () http://marc.info/?l=bugtraq&m=101415804625292&w=2 - | |
References | () http://marc.info/?l=bugtraq&m=101422432123898&w=2 - | |
References | () http://www.debian.org/security/2002/dsa-114 - Patch, Vendor Advisory | |
References | () http://www.iss.net/security_center/static/8240.php - | |
References | () http://www.securityfocus.com/bid/4125 - |
Information
Published : 2002-05-31 04:00
Updated : 2025-04-03 01:03
NVD link : CVE-2002-0300
Mitre link : CVE-2002-0300
CVE.ORG link : CVE-2002-0300
JSON object : View
Products Affected
gnujsp
- gnujsp
CWE