Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The default configuration of the jserv-status handler in jserv.conf in Apache JServ 1.1.2 includes an "allow from 127.0.0.1" line, which allows local users to discover JDBC passwords or other sensitive information via a direct request to the jserv/ URI.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Apache JServ jserv.conf jserv-status处理器配置错误漏洞
Vulnerability Description
Apache JServ 1.1.2的jserv.conf的jserv-status处理器的默认配置包含“allow from 127.0.0.1”线路。本地用户可借助jserv/ URI的直接请求发现JDBC密码或者其他敏感信息。
CVSS Information
N/A
Vulnerability Type
N/A