Sun Java System Application Server 7.0/8.0 - Remote Installation Full Path Disclosure

EDB-ID:

24148

CVE:

N/A




Platform:

Multiple

Date:

2004-05-27


source: https://www.securityfocus.com/bid/10424/info

It is reported that Java System Application Server is prone to a remote installation path disclosure vulnerability. This issue is due to a failure of the application to properly filter user requests.

Successful exploitation of this issue may allow an attacker to gain sensitive information about the file system that may aid in launching more direct attacks against the system. 

http://www.example.com:8080////
http://www.example.com:8080////CON