First published: Fri Oct 13 2000(Updated: )
BEA WebLogic 5.1.x allows remote attackers to read source code for parsed pages by inserting /*.shtml/ into the URL, which invokes the SSIServlet.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
BEA Weblogic Server | =5.1-sp11 | |
BEA Weblogic Server | =5.1-sp7 | |
BEA Weblogic Server | =5.1-sp8 | |
BEA Weblogic Server | =5.1-sp2 | |
BEA Weblogic Server | =5.1-sp5 | |
BEA Weblogic Server | =5.1 | |
BEA Weblogic Server | =5.1 | |
BEA Weblogic Server | =5.1-sp9 | |
BEA Weblogic Server | =5.1-sp3 | |
BEA Weblogic Server | =5.1-sp12 | |
BEA Weblogic Server | =5.1-sp1 | |
BEA Weblogic Server | =5.1 | |
BEA Weblogic Server | =5.1-sp6 | |
BEA Weblogic Server | =5.1-sp10 | |
BEA Weblogic Server | =5.1-sp4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.