VulnerabilityModified
CVE-2005-3747
Unspecified vulnerability in Jetty before 5.1.6 allows remote attackers to obtain source code of JSP pages, possibly involving requests for .jsp files with URL-encoded backslash ("%5C") characters.
MEDIUM 5.0EPSS 4.39%
Does this matter?
Lower severity and a low EPSS score (4.39%). Track it; it rarely justifies an emergency change on its own.
Description
Unspecified vulnerability in Jetty before 5.1.6 allows remote attackers to obtain source code of JSP pages, possibly involving requests for .jsp files with URL-encoded backslash ("%5C") characters. NOTE: this might be the same issue as CVE-2006-2758.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 4.39% probability · 91th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- mortbay/jetty
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/17659Patch, Vendor Advisory
- http://secunia.com/advisories/22669Vendor Advisory
- http://sourceforge.net/project/shownotes.php?release_id=372086&group_id=7322Patch
- http://www.securityfocus.com/archive/1/450315/100/0/threaded
- http://www.securityfocus.com/bid/15515Patch
- http://www.vupen.com/english/advisories/2005/2515Vendor Advisory
- http://secunia.com/advisories/17659Patch, Vendor Advisory
- http://secunia.com/advisories/22669Vendor Advisory
- http://sourceforge.net/project/shownotes.php?release_id=372086&group_id=7322Patch
- http://www.securityfocus.com/archive/1/450315/100/0/threaded
- http://www.securityfocus.com/bid/15515Patch
- http://www.vupen.com/english/advisories/2005/2515Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.