Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2010-3718

Опубликовано: 10 фев. 2011
Источник: ubuntu
Приоритет: low
CVSS2: 1.2

Описание

Apache Tomcat 7.0.0 through 7.0.3, 6.0.x, and 5.5.x, when running within a SecurityManager, does not make the ServletContext attribute read-only, which allows local web applications to read or write files outside of the intended working directory, as demonstrated using a directory traversal attack.

РелизСтатусПримечание
dapper

DNE

devel

DNE

hardy

ignored

karmic

DNE

lucid

DNE

maverick

DNE

natty

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
dapper

DNE

devel

not-affected

6.0.28-10
hardy

DNE

karmic

released

6.0.20-2ubuntu2.4
lucid

released

6.0.24-2ubuntu1.7
maverick

released

6.0.28-2ubuntu1.2
natty

not-affected

6.0.28-10
upstream

released

6.0.28-10

Показывать по

1.2 Low

CVSS2

Связанные уязвимости

redhat
больше 14 лет назад

Apache Tomcat 7.0.0 through 7.0.3, 6.0.x, and 5.5.x, when running within a SecurityManager, does not make the ServletContext attribute read-only, which allows local web applications to read or write files outside of the intended working directory, as demonstrated using a directory traversal attack.

nvd
больше 14 лет назад

Apache Tomcat 7.0.0 through 7.0.3, 6.0.x, and 5.5.x, when running within a SecurityManager, does not make the ServletContext attribute read-only, which allows local web applications to read or write files outside of the intended working directory, as demonstrated using a directory traversal attack.

debian
больше 14 лет назад

Apache Tomcat 7.0.0 through 7.0.3, 6.0.x, and 5.5.x, when running with ...

github
около 3 лет назад

Improper Limitation of a Pathname to a Restricted Directory in Apache Tomcat

oracle-oval
около 14 лет назад

ELSA-2011-0791: tomcat6 security and bug fix update (MODERATE)

1.2 Low

CVSS2