5
CVSSv2

CVE-2005-1112

Published: 02/05/2005 Updated: 11/07/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

IBM WebSphere Application Server 6.0 and previous versions, when sharing the document root of the web server, allows remote malicious users to obtain the source code for Java Server Pages (.jsp) via an HTTP request with an invalid Host header, which causes the page to be processed by the web server instead of the JSP engine.

Vulnerable Product Search on Vulmon Subscribe to Product

ibm websphere application server 5.0.2.5

ibm websphere application server 5.0.2.6

ibm websphere application server 5.0.2.7

ibm websphere application server 5.1.1

ibm websphere application server 5.1.1.1

ibm websphere application server 5.0

ibm websphere application server 5.0.1

ibm websphere application server 5.0.2.8

ibm websphere application server 5.0.2.9

ibm websphere application server 5.1.1.2

ibm websphere application server 5.1.1.3

ibm websphere application server 5.0.2

ibm websphere application server 5.0.2.1

ibm websphere application server 5.1.0

ibm websphere application server 5.1.0.2

ibm websphere application server 6.0

ibm websphere application server 5.0.2.3

ibm websphere application server 5.0.2.4

ibm websphere application server 5.1.0.4

ibm websphere application server 5.1.0.5

Exploits

source: wwwsecurityfocuscom/bid/13160/info A remote JSP source disclosure vulnerability reportedly affects the IBM WebSphere Application Server This issue is due to a failure of the application to properly handle various requests under certain circumstances It should be noted that this issue only arises when the Web serve and applicati ...