
CVE-2004-2478
https://notcve.org/view.php?id=CVE-2004-2478
31 Dec 2004 — Unspecified vulnerability in Jetty HTTP Server, as used in (1) IBM Trading Partner Interchange before 4.2.4, (2) CA Unicenter Web Services Distributed Management (WSDM) before 3.11, and possibly other products, allows remote attackers to read arbitrary files via a .. (dot dot) in the URL. • http://lists.grok.org.uk/pipermail/full-disclosure/2006-October/049846.html •

CVE-2002-1533 – Jetty 4.1 Servlet Engine - Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2002-1533
18 Mar 2003 — Cross-site scripting (XSS) vulnerability in Jetty JSP servlet engine allows remote attackers to insert arbitrary HTML or script via an HTTP request to a .jsp file whose name contains the malicious script and some encoded linefeed characters (%0a). Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en Jetty JSP servlet engine permite a atacantes remotos insertar HTML arbitrario o rutinas vía petición HTTP a un fichero .jsp cuyo nombre contiene la rutina maliciosa y algunos caracteres de nueva ... • https://www.exploit-db.com/exploits/21875 •

CVE-2002-1178 – Jetty 3.1.6/3.1.7/4.1 Servlet Engine - Arbitrary Command Execution
https://notcve.org/view.php?id=CVE-2002-1178
11 Oct 2002 — Directory traversal vulnerability in the CGIServlet for Jetty HTTP server before 4.1.0 allows remote attackers to execute arbitrary commands via ..\ (dot-dot backslash) sequences in an HTTP request to the cgi-bin directory. Vulnerabilidad de atravesamiento de directorios en el CGIServlet en Jetty HHTP server anteriores a 4.1.0 permite a atacantes remotos leer ficheros arbitrarios mediante secuencias .. (punto punto barra invertida) en peticiones HTTP al directorio cgi-bin. • https://www.exploit-db.com/exploits/21895 •