tomcat-dev mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "Bill Barker" <wbar...@wilshire.com>
Subject Re: [PATCH] Potential security problem with '?' in jsp file name TC3.3B1
Date Wed, 22 Aug 2001 21:55:11 GMT
I've confirmed that this also happens with TC3.3B1 stand-alone:

$ telnet localhost 8080
GET /%3f%41%3d%42.jsp HTTP/1.0

<insert directory listing here>
----- Original Message -----
From: "William Barker" <william.barker@wilshire.com>
To: <tomcat-dev@jakarta.apache.org>
Sent: Wednesday, August 15, 2001 2:48 PM
Subject: [PATCH] Potential security problem with '?' in jsp file name
TC3.3B1


> Using:
>  Apache 1.3.17
> TC3.3 B1
>  Ajp13
> Java 1.3.1
>
> making the request http://myserver/%3f%41%3d%42.jsp was interpreted as a
> request for the file "/?A=B.jsp".  JspInterceptor then happily creates a
> page containing the contents of the ROOT directory.  The attached patch
> forbids such silliness.
>


Mime
View raw message