Vulnerabilities > CVE-2002-0893 - Unspecified vulnerability in NEW Atlanta Communications Servletexec Isapi 4.1
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Directory traversal vulnerability in NewAtlanta ServletExec ISAPI 4.1 allows remote attackers to read arbitrary files via a URL-encoded request to com.newatlanta.servletexec.JSP10Servlet containing "..%5c" (modified dot-dot) sequences.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description | NewAtlanta ServletExec/ISAPI 4.1 File Disclosure Vulnerability. CVE-2002-0893. Remote exploit for windows platform |
id | EDB-ID:21470 |
last seen | 2016-02-02 |
modified | 2002-05-22 |
published | 2002-05-22 |
reporter | Matt Moore |
source | https://www.exploit-db.com/download/21470/ |
title | NewAtlanta ServletExec/ISAPI 4.1 File Disclosure Vulnerability |
Nessus
NASL family | CGI abuses |
NASL id | SERVLETEXEC_FILE_READING.NASL |
description | By invoking the JSPServlet directly it is possible to read the contents of files within the webroot that would not normally be accessible (global.asa, for example.) When attempting to retrieve ASP pages it is common to see many errors due to their similarity to JSP pages in syntax, and hence only fragments of these pages are returned. Text files can generally be read without problem. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 10959 |
published | 2002-05-22 |
reporter | This script is Copyright (C) 2002-2018 Matt Moore |
source | https://www.tenable.com/plugins/nessus/10959 |
title | ServletExec 4.1 ISAPI com.newatlanta.servletexec.JSP10Servlet Traversal Arbitrary File Access |
code |
|
References
- http://archives.neohapsis.com/archives/vulnwatch/2002-q2/0077.html
- http://archives.neohapsis.com/archives/vulnwatch/2002-q2/0077.html
- http://online.securityfocus.com/archive/1/273615
- http://online.securityfocus.com/archive/1/273615
- http://www.iss.net/security_center/static/9140.php
- http://www.iss.net/security_center/static/9140.php
- http://www.securityfocus.com/bid/4795
- http://www.securityfocus.com/bid/4795