Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Apache Tomcat System Path Information Disclosure Vulnerability

An issue has been reported in Apache Tomcat 4.1, which could reveal system path information to remote users.

Submitting malformed requests may cause will reveal an error message containing the absolute path to the web root.

Requests that allegedly cause the condition:

http://target/+/file.jsp
http://target/>/file.jsp
http://target/</file.jsp
http://target/%20/file.jsp







 

Privacy Statement
Copyright 2009, SecurityFocus