Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The Admin Server in Sun Java Active Server Pages (ASP) Server before 4.0.3 stores sensitive information under the web root with insufficient access control, which allows remote attackers to read password hashes and configuration data via direct requests for unspecified documents.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Sun Java ASP服务器 根目录数据信息泄露漏洞
Vulnerability Description
Sun Java System Active Server Pages软件允许组织在各种web服务器和操作系统上部署基于ASP的web应用。 ASP 服务 4.0.3 之前的版本口令和配置数据存储到了应用服务器的根目录,攻击者可以检索到配置数据、口令哈希等敏感信息。
CVSS Information
N/A
Vulnerability Type
N/A