TUCoPS :: Web :: Apps :: tomcat3.htm

Jakarta Tomcat 3.1 - reveals paths
Vulnerability

    Tomcat

Affected

    Tomcat 3.1

Description

    ET LoWNOISE  found following.   Release Build  3.1 of  Tomcat from
    Apache Software Foundation  is the combined  JSP 1.1 and  Servlets
    2.2  reference  implementation  being  developed  under the Apache
    process.  Problem is that it reveals path.  Let's see:

        http://narco.guerrilla.sucks.co:8080/anything.jsp

          Error: 404
          Location: /anything.jsp

          JSP file "/appsrv2/jakarta-tomcat/webapps/ROOT/anything.jsp" not found

Solution

    Nothing yet.

TUCoPS is optimized to look best in Firefox® on a widescreen monitor (1440x900 or better).
Site design & layout copyright © 1986-2024 AOH