5
CVSSv2

CVE-2000-1114

Published: 09/01/2001 Updated: 05/09/2008
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Unify ServletExec AS v3.0C allows remote malicious users to read source code for JSP pages via an HTTP request that ends with characters such as ".", or "+", or "%20".

Vulnerable Product Search on Vulmon Subscribe to Product

unify ewave servletexec 3.0c

unify ewave servletexec 3.0

Exploits

source : wwwsecurityfocuscom/bid/1970/info Unify eWave ServletExec is a Java/Java Servlet engine plug-in for major web servers such as Microsoft IIS, Apache, Netscape Enterprise Server, etc ServletExec will return the source code of JSP files when a HTTP request is appended with one of the following characters: %2E + %2B %5C %20 %00 ...