Blazix Web Server before 1.2.6, when running on Windows, allows remote attackers to obtain the source code of JSP files via (1) . (dot), (2) space, and (3) slash characters in the extension of a URL.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Blazix_web_server | Desiderata_software | * | 1.2.5 (including) |