tomcat-users mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From Cheong Takhoe <>
Subject Tomcat security issue
Date Wed, 18 Oct 2000 05:34:03 GMT

I discovered that Tomcat has a security problem with regards to the way it
works with the handlers.

if you have a file x.jsp
when you access it through the web browser, http://<hostname>/x.jsp\
with the \ there,

it opens up the source code....

I don't know whether this is similar on a non-NT platform. 
any ideas about this? solutions?

Cheong Takhoe

View raw message