Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2006-2758

Опубликовано: 18 нояб. 2005
Источник: redhat
CVSS3: 5.3

Описание

Directory traversal vulnerability in jetty 6.0.x (jetty6) beta16 allows remote attackers to read arbitrary files via a %2e%2e%5c (encoded ../) in the URL. NOTE: this might be the same issue as CVE-2005-3747.

A flaw was found in Jetty. This issue could allow a remote attacker to send a specially-crafted URL request containing hexadecimal URL encoded "dot-dot" sequences (%2e%2e%5c) to traverse directories and view files and folders outside of the web root directory.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7jettyNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=2187715jetty: Jetty URL encoded format directory traversal

5.3 Medium

CVSS3

Связанные уязвимости

nvd
около 19 лет назад

Directory traversal vulnerability in jetty 6.0.x (jetty6) beta16 allows remote attackers to read arbitrary files via a %2e%2e%5c (encoded ../) in the URL. NOTE: this might be the same issue as CVE-2005-3747.

debian
около 19 лет назад

Directory traversal vulnerability in jetty 6.0.x (jetty6) beta16 allow ...

github
больше 3 лет назад

Jetty Directory Traversal Vulnerability

5.3 Medium

CVSS3