WebLogic Displays Source Code

WebLogic can be caused to display source code by using specific syntax to invoke the SSIServlet or FileServlet applications, which ship as part of the platform.

ITPro Today Staff

July 28, 2000

1 Min Read
ITPro Today logo

WebLogic Displays Source Code
Reported July 28, 2000 by Foundstone

VERSIONS AFFECTED

  • BEA Systems WebLogic Enterprise 5.1.x

  • BEA Systems WebLogic Server Express 4.5.X and 5.1.xDESCRIPTION

    WebLogic can be caused to displaysource code by using specific syntax to invoke the SSIServlet or FileServlet applications,which ship as part of the platform.

    DEMONSTRATION

    If a site has a URL, such as that shown in Figure 1 then itssource can be displayed by using the URL as seen in Figure 2:

    Figure 1: http://site.running.weblogic/login.jspFigure 2: http://site.running.weblogic/*.shtml/login.jsp

    In addition, by prefixing a URL with the /ConsoleHelp/ path, a file's source code will bedisplayed. For example, the source code within a file at the URL seen in Figure 3 can beviewed by accessing it via the modified URL seen in Figure 4:Figure 3: http://site.running.weblogic/login.jspFigure 4: http://site.running.weblogic/ConsoleHelp/login.jsp

    VENDOR RESPONSE

    BEA System released a patch for theproblem, available by contacting their support staff.

    CREDIT
    Discovered by Foundstone

Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like