Description
Oracle 9i Application Server 1.0.2 allows remote attackers to obtain the physical path of a file under the server root via a request for a non-existent .JSP file, which leaks the pathname in an error message.
Remediation
References
Related Vulnerabilities
WordPress Plugin Tutor LMS-eLearning and online course solution Cross-Site Request Forgery (2.6.1)
IBM WebSEAL 7PK - Security Features Vulnerability (CVE-2016-3025)
WordPress Plugin Gwolle Guestbook Remote File Inclusion (1.5.3)
WordPress Comment Post Cross-Site Scripting Vulnerability (2.0)
WordPress Plugin GS Insever Portfolio Cross-Site Scripting (1.4.4)