Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2006-3835

Apache Tomcat 5 before 5.5.17 allows remote attackers to list directories via a semicolon (;) preceding a filename with a mapped extension, as demonstrated by URLs ending with /;index.jsp and /;help.do.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.524
EPSS Ranking 97.8%
CVSS Severity
CVSS v2 Score 5.0
References
Products affected by CVE-2006-3835
  • Apache » Tomcat » Version: 5.0.28
    cpe:2.3:a:apache:tomcat:5.0.28
  • Apache » Tomcat » Version: 5.5.12
    cpe:2.3:a:apache:tomcat:5.5.12
  • Apache » Tomcat » Version: 5.5.16
    cpe:2.3:a:apache:tomcat:5.5.16
  • Apache » Tomcat » Version: 5.5.7
    cpe:2.3:a:apache:tomcat:5.5.7
  • Apache » Tomcat » Version: 5.5.9
    cpe:2.3:a:apache:tomcat:5.5.9


Contact Us

Shodan ® - All rights reserved