Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2007-1860

Опубликовано: 25 мая 2007
Источник: ubuntu
Приоритет: untriaged
EPSS Средний
CVSS2: 5

Описание

mod_jk in Apache Tomcat JK Web Server Connector 1.2.x before 1.2.23 decodes request URLs within the Apache HTTP Server before passing the URL to Tomcat, which allows remote attackers to access protected pages via a crafted prefix JkMount, possibly involving double-encoded .. (dot dot) sequences and directory traversal, a related issue to CVE-2007-0450.

РелизСтатусПримечание
dapper

released

1:1.2.14.1-2ubuntu1.1
devel

released

1.2.23-3
edgy

ignored

end of life, was needed
feisty

ignored

end of life, was needed
gutsy

released

1.2.23-3
hardy

released

1.2.23-3
intrepid

released

1.2.23-3
upstream

needs-triage

Показывать по

Ссылки на источники

EPSS

Процентиль: 95%
0.1744
Средний

5 Medium

CVSS2

Связанные уязвимости

redhat
больше 18 лет назад

mod_jk in Apache Tomcat JK Web Server Connector 1.2.x before 1.2.23 decodes request URLs within the Apache HTTP Server before passing the URL to Tomcat, which allows remote attackers to access protected pages via a crafted prefix JkMount, possibly involving double-encoded .. (dot dot) sequences and directory traversal, a related issue to CVE-2007-0450.

nvd
больше 18 лет назад

mod_jk in Apache Tomcat JK Web Server Connector 1.2.x before 1.2.23 decodes request URLs within the Apache HTTP Server before passing the URL to Tomcat, which allows remote attackers to access protected pages via a crafted prefix JkMount, possibly involving double-encoded .. (dot dot) sequences and directory traversal, a related issue to CVE-2007-0450.

debian
больше 18 лет назад

mod_jk in Apache Tomcat JK Web Server Connector 1.2.x before 1.2.23 de ...

github
больше 3 лет назад

mod_jk in Apache Tomcat JK Web Server Connector 1.2.x before 1.2.23 decodes request URLs within the Apache HTTP Server before passing the URL to Tomcat, which allows remote attackers to access protected pages via a crafted prefix JkMount, possibly involving double-encoded .. (dot dot) sequences and directory traversal, a related issue to CVE-2007-0450.

EPSS

Процентиль: 95%
0.1744
Средний

5 Medium

CVSS2