Page 6 of 27 results (0.006 seconds)

CVSS: 5.0EPSS: 0%CPEs: 1EXPL: 1

jetty 6.0.x (jetty6) beta16 allows remote attackers to read arbitrary script source code via a capital P in the .jsp extension, and probably other mixed case manipulations. • http://securitytracker.com/id?1016168 •

CVSS: 5.0EPSS: 0%CPEs: 1EXPL: 2

Directory traversal vulnerability in jetty 6.0.x (jetty6) beta16 allows remote attackers to read arbitrary files via a %2e%2e%5c (encoded ../) in the URL. NOTE: this might be the same issue as CVE-2005-3747. • https://www.exploit-db.com/exploits/18571 http://securitytracker.com/id?1016168 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •