BEA WebLogic 5.1.x allows remote attackers to read source code for parsed pages by inserting /*.shtml/ into the URL, which invokes the SSIServlet.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Weblogic_server | Bea | 5.1 (including) | 5.1 (including) |
Weblogic_server | Bea | 5.1-sp1 (including) | 5.1-sp1 (including) |
Weblogic_server | Bea | 5.1-sp10 (including) | 5.1-sp10 (including) |
Weblogic_server | Bea | 5.1-sp11 (including) | 5.1-sp11 (including) |
Weblogic_server | Bea | 5.1-sp12 (including) | 5.1-sp12 (including) |
Weblogic_server | Bea | 5.1-sp2 (including) | 5.1-sp2 (including) |
Weblogic_server | Bea | 5.1-sp3 (including) | 5.1-sp3 (including) |
Weblogic_server | Bea | 5.1-sp4 (including) | 5.1-sp4 (including) |
Weblogic_server | Bea | 5.1-sp5 (including) | 5.1-sp5 (including) |
Weblogic_server | Bea | 5.1-sp6 (including) | 5.1-sp6 (including) |
Weblogic_server | Bea | 5.1-sp7 (including) | 5.1-sp7 (including) |
Weblogic_server | Bea | 5.1-sp8 (including) | 5.1-sp8 (including) |
Weblogic_server | Bea | 5.1-sp9 (including) | 5.1-sp9 (including) |