The default configuration of BEA WebLogic 3.1.8 through 4.5.1 allows a remote attacker to view source code of a JSP program by requesting a URL which provides the JSP extension in upper case.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2000-06-07 21:00
Updated : 2017-10-09 18:29
NVD link : CVE-2000-0499
Mitre link : CVE-2000-0499
JSON object : View
CWE
Products Affected
bea
- weblogic_server