CVE Vulnerabilities

CVE-2005-2006

Published: Jun 17, 2005 | Modified: Oct 19, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

JBOSS 3.2.2 through 3.2.7 and 4.0.2 allows remote attackers to obtain sensitive information via a GET request (1) with a %. (percent dot), which reveals the installation path or (2) with a % (percent) before a filename, which reveals the contents of the file.

Affected Software

Name Vendor Start Version End Version
Jboss Jboss 3.2.2 (including) 3.2.2 (including)
Jboss Jboss 3.2.3 (including) 3.2.3 (including)
Jboss Jboss 3.2.4 (including) 3.2.4 (including)
Jboss Jboss 3.2.5 (including) 3.2.5 (including)
Jboss Jboss 3.2.6 (including) 3.2.6 (including)
Jboss Jboss 3.2.7 (including) 3.2.7 (including)
Jboss Jboss 4.0.2 (including) 4.0.2 (including)

References