CVE-2008-2938
Apache Tomcat < 6.0.18 - 'utf8' Directory Traversal (PoC)
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
5Exploited in Wild
-Decision
Descriptions
Directory traversal vulnerability in Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16, when allowLinking and UTF-8 are enabled, allows remote attackers to read arbitrary files via encoded directory traversal sequences in the URI, a different vulnerability than CVE-2008-2370. NOTE: versions earlier than 6.0.18 were reported affected, but the vendor advisory lists 6.0.16 as the last affected version.
Una vulnerabilidad de salto de directorio (Directory Traversal) en Apache Tomcat versión 4.1.0 hasta 4.1.37, versión 5.5.0 hasta 5.5.26 y versión 6.0.0 hasta 6.0.16, cuando están habilitados allowLinking y UTF-8, permite a atacantes remotos leer archivos arbitrarios por medio de secuencias de salto de directorio (Directory Traversal) en el URI, una vulnerabilidad diferente a CVE-2008-2370. NOTA: las versiones anteriores a 6.0.18 se informaron afectadas, pero el aviso del proveedor enumera 6.0.16 como la última versión afectada.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2008-06-30 CVE Reserved
- 2008-08-13 CVE Published
- 2010-07-28 First Exploit
- 2024-08-07 CVE Updated
- 2025-03-18 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
References (49)
URL | Date | SRC |
---|---|---|
https://packetstorm.news/files/id/180872 | 2024-08-31 | |
https://packetstorm.news/files/id/180868 | 2024-08-31 | |
https://www.exploit-db.com/exploits/6229 | 2024-08-07 | |
https://www.exploit-db.com/exploits/14489 | 2010-07-28 | |
https://github.com/Naramsim/Offensive | 2018-09-01 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | >= 4.0.0 <= 4.1.37 Search vendor "Apache" for product "Tomcat" and version " >= 4.0.0 <= 4.1.37" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | >= 5.0.0 <= 5.5.26 Search vendor "Apache" for product "Tomcat" and version " >= 5.0.0 <= 5.5.26" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | >= 6.0.0 <= 6.0.16 Search vendor "Apache" for product "Tomcat" and version " >= 6.0.0 <= 6.0.16" | - |
Affected
|