mailing list archives
RESIN ServletExec JSP Source Disclosure Vulnerability(IIS 5)
From: benjurry <benjurry () YEAH NET>
Date: Thu, 23 Nov 2000 13:10:11 +0800
flexibility to choose the right language for the task. Resin's leading XSL (XML stylesheet language) support encourages
separation of content from formatting.
Resin provides a fast servlet runner for IIS and PWS, allowing IIS to run servlets and JSP files.
But On Resin1.2(maybe Resin1.1 also)(Win2k Simplify Chinese version),ServletExec will return the source code of JSP
files when you chage the url to encode ASCII(That is to say,"%2e" instead of ".").
For example, the following URL will display the source of the specified JSP file:
Successful exploitation could lead to the disclosure of sensitive information contained within JSP pages.
I have reported this bug to the vendor,but they do nothing about it.
benjurry () 263 net
Share what I konw,Learn what I don't
- RESIN ServletExec JSP Source Disclosure Vulnerability(IIS 5) benjurry (Nov 25)