Bugtraq mailing list archives

JSP processor 1.1 information disclosure


From: Andy <andrewpremote () yahoo co uk>
Date: 13 Nov 2002 14:38:54 -0000



I've been working with IBM http server 1.0 on AS/400 and when requesting a 
JSP page that doesn't exist the JSP processor returns recursive error with 
a listing of information including the root paths and versions of servlets 
that run on the server.

Is this a known vulnerability/misconfiguration?


Current thread: