Total vulnerabilities in the database
The default configuration of BEA WebLogic 5.1.0 allows a remote attacker to view source code of programs by requesting a URL beginning with /file/, which causes the default servlet to display the file without further processing.
Software | From | Fixed in |
---|---|---|
bea / weblogic_server | 5.1 | 5.1.x |
bea / weblogic_server | 3.1.8 | 3.1.8.x |
bea / weblogic_server | 4.5 | 4.5.x |
bea / weblogic_server | 4.0 | 4.0.x |