ScanAlert Security Advisory - http://www.scanalert.com
Directory Listing in Apache Tomcat 5.x.x
Versions: 5.x.x (5.0.28, 5.5.12, 5.5.9, and 5.5.7 . Confirmed)
Credit: ScanAlert.s Enterprise Services Team.
Apache Tomcat is the servlet container that is used in the official Reference Implementation
for the Java Servlet and JavaServer Pages technologies.
Apache Tomcat can be forced to reveal a complete directory listing for any directory by requesting
a mapped file extension prepended with a semicolon, a reserved character. The file does not need to exist.
# milw0rm.com [2006-07-23]