Information Disclosure Vulnerability in Jigsaw Web Server

An information-disclosure vulnerability exists in Jigsaw Web server 2.2.1 for Windows 2000.

Ken Pfeil

July 18, 2002

1 Min Read
ITPro Today logo in a gray background | ITPro Today

ReportedJuly 17, 2002, by Peter Gründl.

VERSION AFFECTED

  • Jigsaw Web Server 2.2.1 for Windows 2000

 

DESCRIPTION

Aninformation-disclosure vulnerability exists in Jigsaw Web server 2.2.1 forWindows 2000. An attacker who requests “/aux” through HTTP two times cancause the Web server to display an error message containing the physical path tothe Web root.

 


VENDOR RESPONSE

 

The vendor, TheWorld Wide Web Consortium (W3C), recommends that affected users upgradeJigsaw.jar file to the latestbuild.

 

CREDIT
Discovered by PeterGründl.

Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like