CVE-2007-0450

Aliases:GHSA-4prh-gqw8-rgh5
Advisory lineage Upstream: 0 Downstream: 9
Modified
Published: 16 Mar 2007, 22:00
Last modified:07 Aug 2024, 12:19

Vulnerability Summary

Overall Risk (default)
medium
48/100
CVSS Score
5 MEDIUM
v2.0 (nvd)
EPSS Score
90.45% CRITICAL
90% probability +2.62%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

16 Mar 2007, 22:00
Published
Vulnerability first disclosed
07 Aug 2024, 12:19
Last Modified
Vulnerability information updated

Description

Directory traversal vulnerability in Apache HTTP Server and Tomcat 5.x before 5.5.22 and 6.x before 6.0.10, when using certain proxy modules (mod_proxy, mod_rewrite, mod_jk), allows remote attackers to read arbitrary files via a .. (dot dot) sequence with combinations of (1) "/" (slash), (2) "\" (backslash), and (3) URL-encoded backslash (%5C) characters in the URL, which are valid separators in Tomcat but not in Apache.

CVSS Metrics

  • v2.0MEDIUMScore: 5AV:N/AC:L/Au:N/C:P/I:N/A:N

EPSS Trends

Current EPSS score: 90.45% Percentile: 100%

Techniques & Countermeasures

  • CWE-22Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

    The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Affected Systems

  • UnknownHTTP Server

    na

  • UnknownTomcat

    ≥ 5.0.0, < 5.5.22 | ≥ 6.0.0, < 6.0.10

  • org.apache.tomcattomcat

    ≥ 5.0, < 5.5.22 | ≥ 6.0, < 6.0.10

References (70)