BEA Systems WebLogic Server and Express Source Code Disclosure Vulnerability
BID:1378
Info
BEA Systems WebLogic Server and Express Source Code Disclosure Vulnerability
| Bugtraq ID: | 1378 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | Yes |
| Published: | Jun 21 2000 12:00AM |
| Updated: | Jun 21 2000 12:00AM |
| Credit: | Discovered by and posted to Bugtraq on June 21, 2000 by Foundstone Inc. <http://www.foundstone.com>. |
| Vulnerable: |
BEA Systems Weblogic Server 5.1 x BEA Systems Weblogic Server 4.5 x BEA Systems Weblogic Server 4.0 x BEA Systems Weblogic Server 3.1.8 BEA Systems WebLogic Express 5.1 x BEA Systems WebLogic Express 4.5 x BEA Systems WebLogic Express 4.0 x BEA Systems WebLogic Express 3.1.8 |
| Not Vulnerable: | |
Exploit / POC
BEA Systems WebLogic Server and Express Source Code Disclosure Vulnerability
http://target/file/filename
http://target/file/filename
Solution / Fix
BEA Systems WebLogic Server and Express Source Code Disclosure Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
Currently the SecurityFocus staff are not aware of any vendor supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
References
BEA Systems WebLogic Server and Express Source Code Disclosure Vulnerability
References:
References:
- Weblogic (BEA Systems)
- WebLogic Server JSP Configuration (BEA Systems)