Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The default configuration of NewAtlanta ServletExec ISAPI 4.1 allows remote attackers to determine the path of the web root via a direct request to com.newatlanta.servletexec.JSP10Servlet without a filename, which leaks the pathname in an error message.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
NewAtlanta ServletExec/ISAPI路径泄露漏洞
Vulnerability Description
ServletExec/ISAPI是一款运行在Microsoft IIS WEB平台下的Java Servlet/JSP引擎插件,可使用在Microsoft Windows NT/2000/XP系统下的IIS WEB服务程序中。 ServletExec/ISAPI对用户提交的没有文件名的URL请求处理不够正确,可导致远程攻击者获得系统中Web主目录安装路径信息。 远程攻击者可以通过直接请求调用'com.newatlanta.servletexec.JSP10Servlet'类而不带任何文件名,服务程序就会
CVSS Information
N/A
Vulnerability Type
N/A