WebLogic Displays Source Code
WebLogic can be caused to display source code by using specific syntax to invoke the SSIServlet or FileServlet applications, which ship as part of the platform.
July 28, 2000
WebLogic Displays Source Code
Reported July 28, 2000 by Foundstone
VERSIONS AFFECTED
BEA Systems WebLogic Enterprise 5.1.x
BEA Systems WebLogic Server Express 4.5.X and 5.1.xDESCRIPTION
WebLogic can be caused to displaysource code by using specific syntax to invoke the SSIServlet or FileServlet applications,which ship as part of the platform.DEMONSTRATION
If a site has a URL, such as that shown in Figure 1 then itssource can be displayed by using the URL as seen in Figure 2:
Figure 1: http://site.running.weblogic/login.jspFigure 2: http://site.running.weblogic/*.shtml/login.jsp
In addition, by prefixing a URL with the /ConsoleHelp/ path, a file's source code will bedisplayed. For example, the source code within a file at the URL seen in Figure 3 can beviewed by accessing it via the modified URL seen in Figure 4:Figure 3: http://site.running.weblogic/login.jspFigure 4: http://site.running.weblogic/ConsoleHelp/login.jspVENDOR RESPONSE
BEA System released a patch for theproblem, available by contacting their support staff.
CREDIT
Discovered by Foundstone
About the Author
You May Also Like