CVE-2006-2466

Publication date

2006-05-19 10:00:00

Family

mitre

State

PUBLISHED

Description

BEA WebLogic Server 8.1 up to SP4 and 7.0 up to SP6 allows remote attackers to obtain the source code of JSP pages during certain circumstances related to a "timing window" when a compilation error occurs, aka the "JSP showcode vulnerability."