Apache Tomcat System Path Information Disclosure Vulnerability
BID:4557
Info
Apache Tomcat System Path Information Disclosure Vulnerability
| Bugtraq ID: | 4557 |
| Class: | Configuration Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 19 2002 12:00AM |
| Updated: | Apr 19 2002 12:00AM |
| Credit: | Discovered by Wang Yun <[email protected]>. |
| Vulnerable: |
Apache Tomcat 4.1 |
| Not Vulnerable: | |
Discussion
Apache Tomcat System Path Information Disclosure Vulnerability
An issue has been reported in Apache Tomcat 4.1, which could reveal system path information to remote users.
Submitting malformed requests may cause will reveal an error message containing the absolute path to the web root.
Requests that allegedly cause the condition:
http://target/+/file.jsp
http://target/>/file.jsp
http://target/</file.jsp
http://target/%20/file.jsp
An issue has been reported in Apache Tomcat 4.1, which could reveal system path information to remote users.
Submitting malformed requests may cause will reveal an error message containing the absolute path to the web root.
Requests that allegedly cause the condition:
http://target/+/file.jsp
http://target/>/file.jsp
http://target/</file.jsp
http://target/%20/file.jsp
Exploit / POC
Apache Tomcat System Path Information Disclosure Vulnerability
No exploit code is required.
No exploit code is required.
Solution / Fix
Apache Tomcat System Path Information Disclosure Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.