Get a Pentest and security assessment of your IT network.

Advisories

iDEFENSE Security Advisory 2008-06-03.3

iDefense Security Advisory 06.03.08 – Remote exploitation of multiple directory traversal vulnerabilities in Sun Microsystem’s Java System Active Server Pages allows attackers to obtain the contents of, and delete, sensitive files on the system. Both vulnerabilities exist within ASP applications included with the product. When accessed via the administration server, the ASP engine does not prevent directory traversal using the “../” construct. By supplying a specially crafted HTTP request to one of the affected ASP applications, an attacker is able to read from arbitrary files. One of the applications will disclose only the first and third lines of the file. Once the application is finished processing the file, it will delete it. iDefense has confirmed the existence of these vulnerabilities within version 4.0.2 of Sun Microsystems Inc.’s Java System Active Server Pages. Older versions are suspected to be vulnerable.

 

You can download this advisory from the following link: https://packetstormsecurity.com/files/download/67000/06.03.08-3.txt

Source: https://packetstormsecurity.com/files/67000/iDEFENSE-Security-Advisory-2008-06-03.3.html

Related posts
Advisories

Ubuntu Security Notice 93-1

Advisories

Secunia Security Advisory 18018

Advisories

Secunia Security Advisory 20784

Advisories

Secunia Security Advisory 23739