Information Disclosure Vulnerability in Jigsaw Web Server
An information-disclosure vulnerability exists in Jigsaw Web server 2.2.1 for Windows 2000.
Ken Pfeil
July 18, 2002
1 Min Read
ReportedJuly 17, 2002, by Peter Gründl.
VERSION AFFECTED
Jigsaw Web Server 2.2.1 for Windows 2000
DESCRIPTION
Aninformation-disclosure vulnerability exists in Jigsaw Web server 2.2.1 forWindows 2000. An attacker who requests “/aux” through HTTP two times cancause the Web server to display an error message containing the physical path tothe Web root.
VENDOR RESPONSE
The vendor, TheWorld Wide Web Consortium (W3C), recommends that affected users upgradeJigsaw.jar file to the latestbuild.
CREDIT
Discovered by PeterGründl.
About the Author
Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.
You May Also Like