Vulnerabilities > CVE-2002-1178 - Unspecified vulnerability in Jetty Http Server

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
jetty
exploit available

Summary

Directory traversal vulnerability in the CGIServlet for Jetty HTTP server before 4.1.0 allows remote attackers to execute arbitrary commands via ..\ (dot-dot backslash) sequences in an HTTP request to the cgi-bin directory.

Vulnerable Configurations

Part Description Count
Application
Jetty
1

Exploit-Db

descriptionJetty 3.1.6/3.1.7/4.1 Servlet Engine Arbitrary Command Execution Vulnerability. CVE-2002-1178. Webapps exploit for cgi platform
idEDB-ID:21895
last seen2016-02-02
modified2002-10-02
published2002-10-02
reporterMatt Moore
sourcehttps://www.exploit-db.com/download/21895/
titleJetty 3.1.6/3.1.7/4.1 Servlet Engine Arbitrary Command Execution Vulnerability