CVE-2006-2758: Path Traversal
Directory traversal vulnerability in jetty 6.0.x (jetty6) beta16 allows remote attackers to read arbitrary files via a %2e%2e%5c (encoded ../) in the URL. NOTE: this might be the same issue as CVE-2005-3747.
Other sources
Directory traversal vulnerability in jetty 6.0.x (jetty6) beta16 allows remote attackers to read arbitrary files via a %2e%2e%5c (encoded ../) in the URL. NOTE: this might be the same issue as CVE-2005-3747.
— GitHub
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-2758?
CVE-2006-2758 has been assigned a moderate severity rating due to its potential for unauthorized file access.
How do I fix CVE-2006-2758?
To fix CVE-2006-2758, upgrade to a version of Jetty later than 6.0.beta16 to mitigate the directory traversal vulnerability.
What software is affected by CVE-2006-2758?
CVE-2006-2758 affects Jetty version 6.0.beta16 and earlier versions.
What type of vulnerability is CVE-2006-2758?
CVE-2006-2758 is classified as a directory traversal vulnerability allowing remote file reading.
Can CVE-2006-2758 lead to sensitive data exposure?
Yes, CVE-2006-2758 can allow attackers to access sensitive files on the server, leading to potential data exposure.