gnujsp 1.0.0 and 1.0.1 allows remote attackers to list directories, read source code of certain scripts, and bypass access restrictions by directly requesting the target file from the gnujsp servlet, which does not work around a limitation of JServ and does not process the requested file.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2002-05-30 21:00
Updated : 2016-10-17 19:18
NVD link : CVE-2002-0300
Mitre link : CVE-2002-0300
JSON object : View
CWE
Products Affected
gnujsp
- gnujsp