Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Directory traversal vulnerability in NewAtlanta ServletExec ISAPI 4.1 allows remote attackers to read arbitrary files via a URL-encoded request to com.newatlanta.servletexec.JSP10Servlet containing "..%5c" (modified dot-dot) sequences.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
NewAtlanta ServletExec/ISAPI远程文件泄露漏洞
Vulnerability Description
ServletExec/ISAPI是一款运行在Microsoft IIS WEB平台下的Java Servlet/JSP引擎插件,可使用在Microsoft Windows NT/2000/XP系统下的IIS WEB服务程序中。 ServletExec/ISAPI对用户提交的特殊URL请求处理不够正确,可导致远程攻击者访问Web主目录中任意文件的内容。 ServletExec/ISAPI对unicode编码处理不正确,攻击者可以提交包含unicode字符的特殊URL请求,以Web进程的权限查看Web主目录
CVSS Information
N/A
Vulnerability Type
N/A