IBM Websphere/NetCommerce3 3.1.2 allows remote attackers to determine the real path of the server by directly calling the macro.d2w macro with a NOEXISTINGHTMLBLOCK argument.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Net.commerce | Ibm | 3.1.2 (including) | 3.1.2 (including) |
Websphere_application_server | Ibm | 5.1.0.3 (including) | 5.1.0.3 (including) |