Unity eWave ServletExec Exposes Source Code

 
Unity eWave ServletExec Exposes Source Code
Reported June 6 by
Niclas Vikstrom

VERSIONS EFFECTED
ServletExec 3.0

DESCRIPTION

The ServletExec software exposes source code for its files if ".JSP" is appended to the end of a generated URL.

VENDOR RESPONSE

The vendor is aware of this problem however however no response was known at the time of this writing.

CREDITS
Discovered and reported by Niclas Vikstrom

Hide comments

Comments

  • Allowed HTML tags: <em> <strong> <blockquote> <br> <p>

Plain text

  • No HTML tags allowed.
  • Web page addresses and e-mail addresses turn into links automatically.
  • Lines and paragraphs break automatically.
Publish