Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2007-1860

Опубликовано: 25 мая 2007
Источник: nvd
CVSS2: 5
EPSS Средний

Описание

mod_jk in Apache Tomcat JK Web Server Connector 1.2.x before 1.2.23 decodes request URLs within the Apache HTTP Server before passing the URL to Tomcat, which allows remote attackers to access protected pages via a crafted prefix JkMount, possibly involving double-encoded .. (dot dot) sequences and directory traversal, a related issue to CVE-2007-0450.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:apache:tomcat_jk_web_server_connector:*:*:*:*:*:*:*:*
Версия до 1.2.22 (включая)

EPSS

Процентиль: 96%
0.24507
Средний

5 Medium

CVSS2

Дефекты

CWE-22

Связанные уязвимости

ubuntu
почти 19 лет назад

mod_jk in Apache Tomcat JK Web Server Connector 1.2.x before 1.2.23 decodes request URLs within the Apache HTTP Server before passing the URL to Tomcat, which allows remote attackers to access protected pages via a crafted prefix JkMount, possibly involving double-encoded .. (dot dot) sequences and directory traversal, a related issue to CVE-2007-0450.

redhat
почти 19 лет назад

mod_jk in Apache Tomcat JK Web Server Connector 1.2.x before 1.2.23 decodes request URLs within the Apache HTTP Server before passing the URL to Tomcat, which allows remote attackers to access protected pages via a crafted prefix JkMount, possibly involving double-encoded .. (dot dot) sequences and directory traversal, a related issue to CVE-2007-0450.

debian
почти 19 лет назад

mod_jk in Apache Tomcat JK Web Server Connector 1.2.x before 1.2.23 de ...

github
почти 4 года назад

mod_jk in Apache Tomcat JK Web Server Connector 1.2.x before 1.2.23 decodes request URLs within the Apache HTTP Server before passing the URL to Tomcat, which allows remote attackers to access protected pages via a crafted prefix JkMount, possibly involving double-encoded .. (dot dot) sequences and directory traversal, a related issue to CVE-2007-0450.

EPSS

Процентиль: 96%
0.24507
Средний

5 Medium

CVSS2

Дефекты

CWE-22