Exploit Apache Tomcat 4.0.3 - Requests Containing MS-DOS Device Names Information Disclosure

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
31551
Проверка EDB
  1. Пройдено
Автор
SECURITY CURMUDGEON
Тип уязвимости
REMOTE
Платформа
MULTIPLE
CVE
cve-2005-4703
Дата публикации
2005-10-14
Код:
source: https://www.securityfocus.com/bid/28484/info

Apache Tomcat is prone to an information-disclosure vulnerability when handling requests that contain MS-DOS device names.

Attackers can leverage this issue to obtain potentially sensitive data that could aid in other attacks.

Tomcat 4.0.3 running on Windows is vulnerable; other versions may also be affected.

The following example request is available:

GET /lpt9.xtp
 
Источник
www.exploit-db.com

Похожие темы