PT-2002-1902 · New Atlanta · Servletexec Isapi

Published

2002-10-04

·

Updated

2008-09-05

·

CVE-2002-0892

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions: NewAtlanta ServletExec ISAPI version 4.1
Description: The default configuration of the software allows remote attackers to determine the path of the web root via a direct request to "com.newatlanta.servletexec.JSP10Servlet" without a filename, which leaks the pathname in an error message.
Recommendations: For NewAtlanta ServletExec ISAPI version 4.1, consider configuring the software to not leak the pathname in error messages, or restrict access to the com.newatlanta.servletexec.JSP10Servlet to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-0892

Affected Products

Servletexec Isapi