Vulnerabilities
Vulnerable Software
Orion Application Server before 2.0.7, when running on Windows, allows remote attackers to obtain the source code of JSP files via (1) . (dot) and (2) space characters in the extension of a URL.
CVSS Score
5.0
EPSS Score
0.013
Published
2006-03-24
Orion Application Server 1.5.3, when running on Windows, allows remote attackers to retrieve files in the WEB-INF directory, which contains Java class files and configuration information, via a request to the WEB-INF directory with a trailing dot ("WEB-INF.").
CVSS Score
5.0
EPSS Score
0.003
Published
2002-12-31


Contact Us

Shodan ® - All rights reserved