多中WEB服务器的通用JSp源代码暴露漏洞,多中WEB服务器的通用JSp源代码暴露漏洞
【 tulaoshi.com - Java 】
bugtraq id 1328Many webservers are case-sensitive, but do not have all possible combinations of cases in mapped extensions mapped properly.
By changing the letters in a JSP or a JHTML file extension from lower case to upper case (eg: .jsp or .jhtml becomes .JSP or .JHTML) in a URL the server does not recognize the file extension and sends the file normally. In that manner, a user is able to access the source code to those specific files.
(本文来源于图老师网站,更多请访问http://www.tulaoshi.com/java/)来源:http://www.tulaoshi.com/n/20160129/1487544.html
看过《多中WEB服务器的通用JSp源代码暴露漏洞》的人还看了以下文章 更多>>