PT-2002-1902 · New Atlanta · Servletexec Isapi
Published
2002-10-04
·
Updated
2008-09-05
·
CVE-2002-0892
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
NewAtlanta ServletExec ISAPI version 4.1
Description:
The default configuration of the software allows remote attackers to determine the path of the web root via a direct request to "com.newatlanta.servletexec.JSP10Servlet" without a filename, which leaks the pathname in an error message.
Recommendations:
For NewAtlanta ServletExec ISAPI version 4.1, consider configuring the software to not leak the pathname in error messages, or restrict access to the com.newatlanta.servletexec.JSP10Servlet to minimize the risk of exploitation.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Servletexec Isapi