|
|
| |
| InfronTech's J2EE Web Application Server, WebTide, is a localized product of PowerTier 7.0 developed by Persistence Software. The WebTide has a vulnerability that allows remote attackers to disclose directories' and files' content by sending the server a special HTTP request. |
| |
Credit:
The information has been provided by SSR Team.
|
| |
Vulnerable systems:
* InfronTech WebTide version 7.04
Immune systems:
* InfronTech WebTide version 7.05
By requesting a URL such as:
http://www.example.com/%3f.jsp
It is possible to cause the WebTide server to return the content of the directory instead of displaying the default HTML file. The same goes for JSP files, instead of running them, their source code will be disclosed.
|
|
|