[19991] in bugtraq

home help back first fref pref prev next nref lref last post

Re: CHINANSL Security Advisory(CSA-200109)

daemon@ATHENA.MIT.EDU (lovehacker)
Mon Apr 2 01:11:09 2001

Message-ID:  <20010402035651.20063.qmail@securityfocus.com>
Date:         Mon, 2 Apr 2001 03:56:51 -0000
Reply-To: lovehacker@263.NET
From: lovehacker <lovehacker@263.NET>
To: BUGTRAQ@SECURITYFOCUS.COM

HI Sverre:
Thanks your reply.
your website is very nice.
Today,I download Tomcat 4.0-b2 but it still can reveal 
script source code by special URL.
please see CHINANSL Security Advisory (CSA-
200110).

thanks again.
lovehacker
All Rights Reserved.
http://www.chinansl.com
lovehacker@chinansl.com

> [lovehacker]
> 
> |   Topic:Tomcat 4.0-b1 for winnt/2000 show ".jsp"
> |   source Vulnerability. [...]
> 
> |   exploits:
> |   http://target:8080/examples/snp/snoop%2ejsp
> 
> This is the same problem I reported a few days 
ago.  It has already
> been fixed in Tomcat 4.0 beta 2.
> 
> 
> Sverre.
> 
> --
> <URL:mailto:shh@thathost.com>
> <URL:http://shh.thathost.com/>
> 
> 

home help back first fref pref prev next nref lref last post