Hello fellows..

Using RH 7.2, Tomcat 3.3 , apache-1.3.20-16, jdk1.3.1
I was testing my hosts with nessus and it discovered that typing this url at
my browser.. gives me this error

http://my.servername.or.ip:8080/globalllllllllllllllllllllllllllllllllllllll
ll....aaaaaaaaaaaaaaaaasdasdl.jsp
Error: 500
Location:
/globalllllllllllllllllllllllllllllllllllllllll....aaaaaaaaaaaaaaaaasdasdl.j
sp
Internal Servlet Error:

java.lang.NullPointerException
 at java.io.File.(File.java:180)
 at org.apache.tomcat.facade.JasperLiaison.setDependency(Unknown Source)
 at org.apache.tomcat.facade.JasperLiaison.processJspFile(Unknown Source)
 at org.apache.tomcat.facade.JspInterceptor.requestMap(Unknown Source)
 at org.apache.tomcat.core.ContextManager.processRequest(Unknown Source)
 at org.apache.tomcat.core.ContextManager.internalService(Unknown Source)
 at org.apache.tomcat.core.ContextManager.service(Unknown Source)
 at
org.apache.tomcat.modules.server.Http10Interceptor.processConnection(Unknown
Source)
 at org.apache.tomcat.util.net.TcpWorkerThread.runIt(Unknown Source)
 at org.apache.tomcat.util.threads.ThreadPool$ControlRunnable.run(Unknown
Source)
 at java.lang.Thread.run(Thread.java:484)

Oops so, combining this one url with others that nessus give I have other
error that nessus does't give...
http://my.server.ipor.name:8080/servlet/com.newatlanta.servletexec.JSP10Serv
let/..%5c..%5c/globalllllllllllllllllllllllllllllllllllllllll....aaaaaaaaaaa
aaaaaasdasdl.jsp

Error: 403
Location:
/servlet/com.newatlanta.servletexec.JSP10Servlet/..%5c..%5c/globalllllllllll
llllllllllllllllllllllllllllll....aaaaaaaaaaaaaaaaasdasdl.jsp
Unsafe URL

So i went to the site where they explain
http://www.westpoint.ltd.uk/advisories/wp-02-0006.txt!!!
and they explain just about windows, not linux....

what I can't understand is why I'm having this if I'm using linux, there is
something in common at java stuff ????
How can I fix that...????
I've found this
ftp://ftp.newatlanta.com/public/4_1/patches/ServletExec_AS_41.sh
Should I install it ???

thx and regards 4 all



-- 
redhat-list mailing list
unsubscribe mailto:[EMAIL PROTECTED]?subject=unsubscribe
https://listman.redhat.com/mailman/listinfo/redhat-list

Reply via email to