Jetty Double Slash URI Information Disclosure Vulnerability
BID:27117
Info
Jetty Double Slash URI Information Disclosure Vulnerability
| Bugtraq ID: | 27117 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-6672 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 03 2008 12:00AM |
| Updated: | Jan 18 2008 04:48PM |
| Credit: | Greg Wilkins is credited with the discovery of this vulnerability. |
| Vulnerable: |
Jetty Jetty 6.1.6 Jetty Jetty 6.1.5 Igniterealtime Openfire 3.4.3 |
| Not Vulnerable: |
Jetty Jetty 6.1.7 Igniterealtime Openfire 3.4.4 |
Discussion
Jetty Double Slash URI Information Disclosure Vulnerability
Jetty is prone to an information-disclosure vulnerability because it fails to sufficiently sanitize user-supplied input.
An attacker can exploit this issue to view private directories or files within the context of the webserver process. Information obtained may lead to other attacks.
This issue affects Jetty 6.1.5 and 6.1.6.
Jetty is prone to an information-disclosure vulnerability because it fails to sufficiently sanitize user-supplied input.
An attacker can exploit this issue to view private directories or files within the context of the webserver process. Information obtained may lead to other attacks.
This issue affects Jetty 6.1.5 and 6.1.6.
Exploit / POC
Jetty Double Slash URI Information Disclosure Vulnerability
Attackers can exploit this vulnerability with a browser.
Attackers can exploit this vulnerability with a browser.
Solution / Fix
Jetty Double Slash URI Information Disclosure Vulnerability
Solution:
The vendor released an update to address this issue. Please see the references for more information.
Jetty Jetty 6.1.6
Jetty Jetty 6.1.5
Solution:
The vendor released an update to address this issue. Please see the references for more information.
Jetty Jetty 6.1.6
-
Cuyahoga jetty-6.1.7.zip
http://dist.codehaus.org/jetty/jetty-6.1.7/jetty-6.1.7.zip
Jetty Jetty 6.1.5
-
Cuyahoga jetty-6.1.7.zip
http://dist.codehaus.org/jetty/jetty-6.1.7/jetty-6.1.7.zip
References
Jetty Double Slash URI Information Disclosure Vulnerability
References:
References:
- Jetty Double Slash Problem (Jetty)
- Jetty Homepage (Jetty)
- Openfire 3.4.4 has been released (Ignite Realtime)
- Openfire Changelog (Ignite Realtime)
- Vulnerability Note VU#553235 (US-CERT)