Allaire JRun JSP Source Disclosure Vulnerability

Allaire JRun is a web application development suite with JSP and Java Servlets.

A vulnerability exists in JRun which could enable a remote user to gain access to the source code of a known JSP file.

This is achieved when submitting a URL requesting a JSP file appended with '::$DATA'.


 

Privacy Statement
Copyright 2010, SecurityFocus