{"api_version":"1","generated_at":"2026-07-23T09:19:06+00:00","cve":"CVE-2006-0819","urls":{"html":"https://cve.report/CVE-2006-0819","api":"https://cve.report/api/cve/CVE-2006-0819.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2006-0819","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2006-0819"},"summary":{"title":"CVE-2006-0819","description":"Dwarf HTTP Server 1.3.2 allows remote attackers to obtain the source code of JSP files via (1) dot, (2) space, (3) slash, or (4) NULL characters in the filename extension of an HTTP request.","state":"PUBLISHED","assigner":"mitre","published_at":"2006-03-13 19:34:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.8","severity":"","vector":"AV:N/AC:L/Au:N/C:C/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:N/A:N","baseScore":7.8,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://secunia.com/advisories/18962","name":"http://secunia.com/advisories/18962","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"Secunia - Advisories - Dwarf HTTP Server Source Disclosure and Cross-Site Scripting","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securityreason.com/securityalert/576","name":"http://securityreason.com/securityalert/576","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityReason","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2006/0937","name":"http://www.vupen.com/english/advisories/2006/0937","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.osvdb.org/23836","name":"http://www.osvdb.org/23836","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://securitytracker.com/id?1015779","name":"http://securitytracker.com/id?1015779","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Dwarf HTTP Server Discloses JSP Source Code and Permits Cross-Site Scripting Attacks - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"http://www.securityfocus.com/archive/1/427478/100/0/threaded","name":"http://www.securityfocus.com/archive/1/427478/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/25178","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/25178","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/secunia_research/2006-13/advisory","name":"http://secunia.com/secunia_research/2006-13/advisory","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"About Secunia Research | Flexera","mime":"text/plain","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/17123","name":"http://www.securityfocus.com/bid/17123","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Dwarf HTTP Server Multiple Input Validation Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2006-0819","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2006-0819","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2006","cve_id":"819","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"gnome","cpe5":"dwarf_http_server","cpe6":"1.3.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2006","cve_id":"819","cve":"CVE-2006-0819","epss":"0.011180000","percentile":"0.782530000","score_date":"2026-04-17","updated_at":"2026-04-18 00:07:15"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T16:48:56.443Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"ADV-2006-0937","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2006/0937"},{"name":"1015779","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1015779"},{"name":"17123","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/17123"},{"name":"dwarfhttp-extension-information-disclosure(25178)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/25178"},{"name":"20060313 Secunia Research: Dwarf HTTP Server Source Disclosure andCross-Site Scripting","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/427478/100/0/threaded"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://secunia.com/secunia_research/2006-13/advisory"},{"name":"23836","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/23836"},{"name":"576","tags":["third-party-advisory","x_refsource_SREASON","x_transferred"],"url":"http://securityreason.com/securityalert/576"},{"name":"18962","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/18962"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2006-03-13T00:00:00.000Z","descriptions":[{"lang":"en","value":"Dwarf HTTP Server 1.3.2 allows remote attackers to obtain the source code of JSP files via (1) dot, (2) space, (3) slash, or (4) NULL characters in the filename extension of an HTTP request."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-18T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"ADV-2006-0937","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2006/0937"},{"name":"1015779","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1015779"},{"name":"17123","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/17123"},{"name":"dwarfhttp-extension-information-disclosure(25178)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/25178"},{"name":"20060313 Secunia Research: Dwarf HTTP Server Source Disclosure andCross-Site Scripting","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/427478/100/0/threaded"},{"tags":["x_refsource_MISC"],"url":"http://secunia.com/secunia_research/2006-13/advisory"},{"name":"23836","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/23836"},{"name":"576","tags":["third-party-advisory","x_refsource_SREASON"],"url":"http://securityreason.com/securityalert/576"},{"name":"18962","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/18962"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2006-0819","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Dwarf HTTP Server 1.3.2 allows remote attackers to obtain the source code of JSP files via (1) dot, (2) space, (3) slash, or (4) NULL characters in the filename extension of an HTTP request."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"ADV-2006-0937","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2006/0937"},{"name":"1015779","refsource":"SECTRACK","url":"http://securitytracker.com/id?1015779"},{"name":"17123","refsource":"BID","url":"http://www.securityfocus.com/bid/17123"},{"name":"dwarfhttp-extension-information-disclosure(25178)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/25178"},{"name":"20060313 Secunia Research: Dwarf HTTP Server Source Disclosure andCross-Site Scripting","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/427478/100/0/threaded"},{"name":"http://secunia.com/secunia_research/2006-13/advisory","refsource":"MISC","url":"http://secunia.com/secunia_research/2006-13/advisory"},{"name":"23836","refsource":"OSVDB","url":"http://www.osvdb.org/23836"},{"name":"576","refsource":"SREASON","url":"http://securityreason.com/securityalert/576"},{"name":"18962","refsource":"SECUNIA","url":"http://secunia.com/advisories/18962"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2006-0819","datePublished":"2006-03-13T19:00:00.000Z","dateReserved":"2006-02-21T00:00:00.000Z","dateUpdated":"2024-08-07T16:48:56.443Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2006-03-13 19:34:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:N/A:N","baseScore":7.8,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gnome:dwarf_http_server:1.3.2:*:*:*:*:*:*:*","matchCriteriaId":"07C397EB-F084-4F17-B959-B8E075C7A00C"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2006","CveId":"819","Ordinal":"1","Title":"CVE-2006-0819","CVE":"CVE-2006-0819","Year":"2006"},"notes":[{"CveYear":"2006","CveId":"819","Ordinal":"1","NoteData":"Dwarf HTTP Server 1.3.2 allows remote attackers to obtain the source code of JSP files via (1) dot, (2) space, (3) slash, or (4) NULL characters in the filename extension of an HTTP request.","Type":"Description","Title":"CVE-2006-0819"},{"CveYear":"2006","CveId":"819","Ordinal":"2","NoteData":"2006-03-13","Type":"Other","Title":"Published"},{"CveYear":"2006","CveId":"819","Ordinal":"3","NoteData":"2018-10-18","Type":"Other","Title":"Modified"}]}}}