Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2006-2758

Опубликовано: 18 нояб. 2005
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

Directory traversal vulnerability in jetty 6.0.x (jetty6) beta16 allows remote attackers to read arbitrary files via a %2e%2e%5c (encoded ../) in the URL. NOTE: this might be the same issue as CVE-2005-3747.

A flaw was found in Jetty. This issue could allow a remote attacker to send a specially-crafted URL request containing hexadecimal URL encoded "dot-dot" sequences (%2e%2e%5c) to traverse directories and view files and folders outside of the web root directory.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7jettyNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=2187715jetty: Jetty URL encoded format directory traversal

EPSS

Процентиль: 81%
0.01572
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

nvd
больше 19 лет назад

Directory traversal vulnerability in jetty 6.0.x (jetty6) beta16 allows remote attackers to read arbitrary files via a %2e%2e%5c (encoded ../) in the URL. NOTE: this might be the same issue as CVE-2005-3747.

debian
больше 19 лет назад

Directory traversal vulnerability in jetty 6.0.x (jetty6) beta16 allow ...

github
больше 3 лет назад

Jetty Directory Traversal Vulnerability

EPSS

Процентиль: 81%
0.01572
Низкий

5.3 Medium

CVSS3