PT-2002-1902 · New Atlanta · Servletexec Isapi
Publicado
2002-10-04
·
Atualizado
2008-09-05
·
CVE-2002-0892
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
NewAtlanta ServletExec ISAPI version 4.1
Description:
The default configuration of the software allows remote attackers to determine the path of the web root via a direct request to "com.newatlanta.servletexec.JSP10Servlet" without a filename, which leaks the pathname in an error message.
Recommendations:
For NewAtlanta ServletExec ISAPI version 4.1, consider configuring the software to not leak the pathname in error messages, or restrict access to the com.newatlanta.servletexec.JSP10Servlet to minimize the risk of exploitation.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Servletexec Isapi