HTTP: Tomcat .jsp Source Disclosure
This signature detects attempts to exploit a known vulnerability in DefaultServlet, included with Apache Tomcat. Apache Tomcat Server 4.1.10, 4.0.4, and earlier versions are vulnerable. Attackers can view the source of .jsp scripts to obtain critical information such as usernames and passwords.
Extended Description
The servlet 'org.apache.catalina.servlets.DefaultServlet' is included with Apache Tomcat by default. It is possible to use this servlet to view contents of files within the webroot. This includes JSP source code, which may contain sensitive data such as database usernames and passwords.
Affected Products
Sun solaris
srx-branch-12.3
srx-19.3
srx-branch-19.3
vsrx3bsd-19.2
srx-branch-19.4
vsrx-19.4
mx-12.3
mx-19.4
vmx-19.4
mx-19.3
vsrx3bsd-19.4
srx-19.4
vsrx-12.3
vmx-19.3
vsrx-19.2
srx-12.3
Apache_software_foundation
Sun
Hp
5.0