PT-2006-4694 · Apache · Apache Tomcat

Publicado

2006-07-25

·

Atualizado

2022-05-01

·

CVE-2006-3835

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache Tomcat versions prior to 5.5.17
Description The issue allows remote attackers to list directories by inserting a semicolon (;) before a filename with a mapped extension. This is possible because the semicolon is used as a separator for path parameters, which changes the request into a directory request with a path parameter. If directory listings are enabled, a directory listing will be shown. This behavior was considered a security concern and led to changes in the default settings.
Recommendations For Apache Tomcat versions prior to 5.5.17, consider disabling directory listings to minimize the risk of exploitation. As a permanent fix, update to version 5.5.17 or later, where directory listings are disabled by default.

Exploit

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2006-3835
GHSA-WFJ7-MHR5-PCWQ
RHSA-2007:0326
RHSA-2007:0340
RHSA-2007:1069
RHSA-2008:0261
RHSA-2008:0524
RHSA-2010:0602

Produtos afetados

Apache Tomcat