5

CVE-2005-2006

JBOSS 3.2.2 through 3.2.7 and 4.0.2 allows remote attackers to obtain sensitive information via a GET request (1) with a "%." (percent dot), which reveals the installation path or (2) with a % (percent) before a filename, which reveals the contents of the file.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
JbossJboss Version3.2.2
JbossJboss Version3.2.3
JbossJboss Version3.2.4
JbossJboss Version3.2.5
JbossJboss Version3.2.6
JbossJboss Version3.2.7
JbossJboss Version4.0.2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 14.59% 0.938
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N