CVE Vulnerabilities

CVE-2005-2006

Published: Jun 17, 2005 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

JBOSS 3.2.2 through 3.2.7 and 4.0.2 allows remote attackers to obtain sensitive information via a GET request (1) with a %. (percent dot), which reveals the installation path or (2) with a % (percent) before a filename, which reveals the contents of the file.

Affected Software

NameVendorStart VersionEnd Version
JbossJboss3.2.2 (including)3.2.2 (including)
JbossJboss3.2.3 (including)3.2.3 (including)
JbossJboss3.2.4 (including)3.2.4 (including)
JbossJboss3.2.5 (including)3.2.5 (including)
JbossJboss3.2.6 (including)3.2.6 (including)
JbossJboss3.2.7 (including)3.2.7 (including)
JbossJboss4.0.2 (including)4.0.2 (including)

References