Show filters
27 Total Results
Displaying 21-27 of 27
Sort by:
Attacker Value
Unknown
CVE-2006-7166
Disclosure Date: March 20, 2007 (last updated October 04, 2023)
IBM WebSphere Application Server (WAS) 5.1.1.9 and earlier allows remote attackers to obtain JSP source code and other sensitive information via "a specific JSP URL."
0
Attacker Value
Unknown
CVE-2006-6636
Disclosure Date: December 19, 2006 (last updated October 04, 2023)
Unspecified vulnerability in the Utility Classes for IBM WebSphere Application Server (WAS) before 5.1.1.13 and 6.x before 6.0.2.17 has unknown impact and attack vectors.
0
Attacker Value
Unknown
CVE-2006-3232
Disclosure Date: June 27, 2006 (last updated October 04, 2023)
Unspecified vulnerability in IBM WebSphere Application Server before 6.0.2.11 has unknown impact and attack vectors because the "UserNameToken cache was improperly used."
0
Attacker Value
Unknown
CVE-2006-3231
Disclosure Date: June 27, 2006 (last updated October 04, 2023)
Unspecified vulnerability in IBM WebSphere Application Server (WAS) before 6.0.2.11, when fileServingEnabled is true, allows remote attackers to obtain JSP source code and other sensitive information via "URIs with special characters."
0
Attacker Value
Unknown
CVE-2006-2431
Disclosure Date: May 17, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the 500 Internal Server Error page on the SOAP port (8880/tcp) in IBM WebSphere Application Server 5.0.2 and earlier, 5.1.x before 5.1.1.12, and 6.0.2 up to 6.0.2.7, allows remote attackers to inject arbitrary web script or HTML via the URI, which is contained in a FAULTACTOR element on this page. NOTE: some sources have reported the element as "faultfactor," but this is likely erroneous.
0
Attacker Value
Unknown
CVE-2006-1093
Disclosure Date: March 09, 2006 (last updated February 22, 2025)
Unspecified vulnerability in IBM WebSphere 5.0.2.10 through 5.0.2.15 and 5.1.1.4 through 5.1.1.9 allows remote attackers to obtain sensitive information via unknown attack vectors, which causes JSP source code to be revealed.
0
Attacker Value
Unknown
CVE-2005-1112
Disclosure Date: May 02, 2005 (last updated February 22, 2025)
IBM WebSphere Application Server 6.0 and earlier, when sharing the document root of the web server, allows remote attackers to obtain the source code for Java Server Pages (.jsp) via an HTTP request with an invalid Host header, which causes the page to be processed by the web server instead of the JSP engine.
0