[SECURITY] More information on Tomcat 4.0.3

2002-03-06 Thread Remy Maucherat
After additional review, it has been discovered that the security bug fixed in Tomcat 4.0.3 was more severe than originally though, and can be used to remotely browse the server filesystem. To exploit this bug, an attacker would require that some user modifiable data (like a form POST data, or a

Re: [SECURITY] More information on Tomcat 4.0.3

2002-03-07 Thread Richard Murphy
Heads up Tomcatters ... Richard Remy Maucherat wrote: > After additional review, it has been discovered that the security bug fixed > in Tomcat 4.0.3 was more severe than originally though, and can be used to > remotely browse the server filesystem. > > To exploit this bug, an attacker would re