CVE-2007-6672
Published · Updated
25Vexday Risk Score
Prioritize patching. It exploitation observed by VulnCheck.
ssvc Attendepss 3.9%
from disclosure to weapon
Published on NVDJan 8
VulnCheck+6768d
exploitation probability
3.9%top 10% of all CVEs
observed exploitation
yesVulnCheck
Mortbay Jetty 6.1.5 and 6.1.6 allows remote attackers to bypass protection mechanisms and read the source of files via multiple '/' (slash) characters in the URI.
Affected products
n/a · n/aReferences
http://jira.codehaus.org/browse/JETTY-386#action_117699http://jira.codehaus.org/browse/JETTY/fixforversion/13950http://osvdb.org/39855http://secunia.com/advisories/28322http://secunia.com/advisories/28547http://www.igniterealtime.org/community/message/163752http://www.kb.cert.org/vuls/id/553235http://www.securityfocus.com/bid/27117http://www.vupen.com/english/advisories/2008/0079