漏洞信息详情
Bajie Webserver绝对路径泄露漏洞
漏洞简介
Bajie HTTP web server 0.30a版本中的样板Java控制器\"test\"泄露web文档根的实际路径名。
漏洞公告
Remove/disable the offending servlet, /servlet/test/pathInfo/test. This issue has been addressed in Bajie Java HTTP Server versions 0.92 and later.
参考网址
来源: BID 名称: 1521 链接:http://www.securityfocus.com/bid/1521 来源: BUGTRAQ 名称: 20000731 Two security flaws in Bajie Webserver 链接:http://archives.neohapsis.com/archives/bugtraq/2000-07/0426.html
受影响实体
- Bajie Java_http_server:1.0<!--2000-1-1-->
补丁
暂无
还没有评论,来说两句吧...