General Information

JSP Remote File Inclusion

Variants:
Direct Persistent Session 

Vector Type:
Attack

Relevance:
Technology Specific

Layer:
Application-Level

Platforms:
JSP

Target Type:
Web Application

Affected Mechanisms:
Input Validation, Secure Design

Invented In:
01/01/2001

Added In:
08/12/2014


Vector Operation Method:
Malicious inputs can introduce external remote content or external server code into the JSP application


Direct Variant:

JSP Remote File Inclusion

Variant Title:
JSP Remote File Inclusion

Typical Severity:
Critical

Resources:

White Papers:

Learn More:


Persistent Variant:

Stored JSP Remote File Inclusion

Also Known As:
Persistent JSP Remote File Inclusion

Typical Severity:
Critical

Resources:

White Papers:

Learn More:


Session Variant:

JSP Remote File Inclusion via Session Puzzling

Also Known As:
Session JSP Remote File Inclusion

Typical Severity:
Critical

Resources:

White Papers:

Learn More: