First published: Wed Jun 04 2008(Updated: )
Multiple directory traversal vulnerabilities in unspecified ASP applications in Sun Java Active Server Pages (ASP) Server before 4.0.3 allow remote attackers to read or delete arbitrary files via a .. (dot dot) in the Path parameter to the MapPath method.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sun Java Asp Server | <=4.0.2 | |
Sun Java Asp Server | =4.0.1 | |
Sun Java Asp Server | =4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-2403 is considered a high severity vulnerability due to its potential to expose sensitive files to remote attackers.
To mitigate CVE-2008-2403, upgrade your Sun Java Active Server Pages to version 4.0.3 or later to eliminate the directory traversal vulnerability.
CVE-2008-2403 allows remote attackers to perform directory traversal attacks, enabling them to read or delete arbitrary files on the server.
CVE-2008-2403 affects Sun Java Active Server Pages versions up to and including 4.0.2.
CVE-2008-2403 is part of a family of vulnerabilities impacting unspecified ASP applications, indicating a broader potential risk.