Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Orion Application Server before 2.0.7, when running on Windows, allows remote attackers to obtain the source code of JSP files via (1) . (dot) and (2) space characters in the extension of a URL.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Orion Application Server JSP源码泄露漏洞
Vulnerability Description
Orion Application Server是一款功能强大的java应用服务器。 Orion没有正确过滤用户在URL中所提供的文件名扩展,这样攻击者就可以通过发送包含有逗号和空格的特制请求检索JSP文件的源码。
CVSS Information
N/A
Vulnerability Type
N/A