PT-2002-1902 · New Atlanta · Servletexec Isapi

Publicado

2002-10-04

·

Atualizado

2008-09-05

·

CVE-2002-0892

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions: NewAtlanta ServletExec ISAPI version 4.1
Description: The default configuration of the software allows remote attackers to determine the path of the web root via a direct request to "com.newatlanta.servletexec.JSP10Servlet" without a filename, which leaks the pathname in an error message.
Recommendations: For NewAtlanta ServletExec ISAPI version 4.1, consider configuring the software to not leak the pathname in error messages, or restrict access to the com.newatlanta.servletexec.JSP10Servlet to minimize the risk of exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2002-0892

Produtos afetados

Servletexec Isapi