Test Methods ( Detailed Overview )

Here is a list of every test performed by Web Scan Service.

JSP/JHTML Extension Case Change Source Disclosure

Remediation Task

Install patch or upgrade version

WASC Classification

Information Disclosure: Information Leakage

Affected Products

This issue may affect different types of products

Technical Description

This issuemay allow a malicious user to display the source code of arbitrary scripts instead of generated response. The issue is triggered when processing specially crafted HTTP requests containing file extensions with unexpected capitalization.

Fix Recommendation

Because the problem exists on different server types and on with a variety of third party software, we can only recommend to get the latest patches and upgrades for your system.