5
CVSSv2

CVE-2005-3747

Published: 22/11/2005 Updated: 19/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Unspecified vulnerability in Jetty prior to 5.1.6 allows remote malicious users to obtain source code of JSP pages, possibly involving requests for .jsp files with URL-encoded backslash ("%5C") characters. NOTE: this might be the same issue as CVE-2006-2758.

Vulnerable Product Search on Vulmon Subscribe to Product

mortbay jetty 1.0.1

mortbay jetty 1.1

mortbay jetty 3.0.a9

mortbay jetty 3.0.a4

mortbay jetty 3.0.a1

mortbay jetty 3.0.0

mortbay jetty 2.1.b0

mortbay jetty 2.1.1

mortbay jetty 2.1.6

mortbay jetty 2.2

mortbay jetty 1.3.1

mortbay jetty 1.3.2

mortbay jetty 2.0

mortbay jetty 2.0.0

mortbay jetty 2.4.1

mortbay jetty 2.4.0

mortbay jetty 3.0.a92

mortbay jetty 3.0.a91

mortbay jetty 2.2.0

mortbay jetty 2.2.7

mortbay jetty 2.2.8

mortbay jetty 4.2.21

mortbay jetty 4.2.20

mortbay jetty 4.2.22

mortbay jetty 3.1

mortbay jetty 4.2.10

mortbay jetty 1.1.1

mortbay jetty 1.2.0

mortbay jetty 3.0.a6

mortbay jetty 3.0.a3

mortbay jetty 3.0.5

mortbay jetty 3.0.4

mortbay jetty 2.4.7

mortbay jetty 3.0.a99

mortbay jetty 2.1.b1

mortbay jetty 2.1.4

mortbay jetty 2.1.7

mortbay jetty 1.3.0

mortbay jetty 2.0.4

mortbay jetty 2.4.2

mortbay jetty 3.0.a94

mortbay jetty 3.0.a93

mortbay jetty 2.2.1

mortbay jetty 2.2.2

mortbay jetty 2.3.0a

mortbay jetty 2.3.0

mortbay jetty 4.2.18

mortbay jetty 3.0.b05

mortbay jetty 4.2.15

mortbay jetty 4.1.4

mortbay jetty 4.0

mortbay jetty 4.0.6

mortbay jetty 3.1.6

mortbay jetty 4.1.3

mortbay jetty 4.1.d0

mortbay jetty 4.0.1

mortbay jetty 4.1.0

mortbay jetty 3.1.4

mortbay jetty 4.1.b0

mortbay jetty 3.1.0

mortbay jetty 4.1.d2

mortbay jetty 4.0.b1

mortbay jetty 4.1.1

mortbay jetty 4.0.d2

mortbay jetty 3.0.b01

mortbay jetty 4.2.14

mortbay jetty 4.2.0

mortbay jetty 4.0.b2

mortbay jetty 4.0.4

mortbay jetty 4.2.3

mortbay jetty 3.1.1

mortbay jetty 4.0.d3

mortbay jetty 3.1.5

mortbay jetty 4.2.25

mortbay jetty 4.2.23

mortbay jetty 5.0

mortbay jetty 5.0.0

mortbay jetty 4.2.7

mortbay jetty 5.1

mortbay jetty 5.1.11

mortbay jetty 5.1.1

mortbay jetty 5.1.2

mortbay jetty 5.1.3

mortbay jetty 1.0

mortbay jetty 3.0.a7

mortbay jetty 3.0.a2

mortbay jetty 3.0.a0

mortbay jetty 3.0.1

mortbay jetty 2.4.8

mortbay jetty 2.1.0

mortbay jetty 2.1.3

mortbay jetty 1.3.3

mortbay jetty 1.3.4

mortbay jetty 2.0.1

mortbay jetty 2.0.2

mortbay jetty 2.3.5

mortbay jetty 3.0.a90

mortbay jetty 3.0.a98

mortbay jetty 3.0.a97

mortbay jetty 2.2.5

mortbay jetty 2.2.6

mortbay jetty 2.3.3

mortbay jetty 2.3.4

mortbay jetty 2.3.1

mortbay jetty 4.2.16

mortbay jetty 4.2.17

mortbay jetty 3.0.b02

mortbay jetty 4.2.1

mortbay jetty 4.0.3

mortbay jetty 4.1.d1

mortbay jetty 4.2.4

mortbay jetty 4.0.5

mortbay jetty 3.1.2

mortbay jetty 3.1.9

mortbay jetty 4.0.d4

mortbay jetty 4.0.d0

mortbay jetty 4.2

mortbay jetty 4.2.24

mortbay jetty 4.2.9

mortbay jetty 5.1.4

mortbay jetty 5.1.5

mortbay jetty 5.1.0

mortbay jetty

mortbay jetty 4.2.19

mortbay jetty 3.1.8

mortbay jetty 4.2.5

mortbay jetty 3.0.a8

mortbay jetty 3.0.a5

mortbay jetty 3.0.3

mortbay jetty 3.0.2

mortbay jetty 3.0.6

mortbay jetty 2.4.6

mortbay jetty 2.4.9

mortbay jetty 2.1.2

mortbay jetty 2.1.5

mortbay jetty 3.0

mortbay jetty 1.3.5

mortbay jetty 2.0.3

mortbay jetty 2.0.5

mortbay jetty 2.4.5

mortbay jetty 2.4.4

mortbay jetty 2.4.3

mortbay jetty 3.0.a96

mortbay jetty 3.0.a95

mortbay jetty 2.2.3

mortbay jetty 2.2.4

mortbay jetty 2.3.2

mortbay jetty 4.2.27

mortbay jetty 4.2.12

mortbay jetty 3.0.b04

mortbay jetty 3.0.b03

mortbay jetty 4.2.2

mortbay jetty 4.0.0

mortbay jetty 3.1.7

mortbay jetty 4.0.2

mortbay jetty 3.1.3

mortbay jetty 4.1.b1

mortbay jetty 4.0.b0

mortbay jetty 4.1.2

mortbay jetty 4.0.d1

mortbay jetty 4.2.26

mortbay jetty 4.2.11

mortbay jetty 4.2.6

mortbay jetty 4.2.8_01

Vendor Advisories

Debian Bug report logs - #340582 CVE-2005-3747: Incorrect input validation of HTTP requests Package: jetty; Maintainer for jetty is Debian Java Maintainers <pkg-java-maintainers@listsaliothdebianorg>; Reported by: Moritz Muehlenhoff <jmm@inutilorg> Date: Thu, 24 Nov 2005 11:03:07 UTC Severity: grave Tags: securit ...

Exploits

Promise WebPAM v22013 Multiple Remote Vulnerabilities Vendor: Promise Technology, Inc Product web page: wwwpromisecom Affected version: 22013 Summary: WebPAM is a web based Promise Array Management Software that's easy-to use, designed to simplify RAID storage management WebPAM is specifically designed for Promise HBA WebPAM ca ...