Back to search
CVE-2006-3835
Published: Jul 25, 2006
Modified: Aug 7, 2024
PUBLISHED
Description
Apache Tomcat 5 before 5.5.17 allows remote attackers to list directories via a semicolon (;) preceding a filename with a mapped extension, as demonstrated by URLs ending with /;index.jsp and /;help.do.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
19106
vdb-entry
x_refsource_BID
http://tomcat.apache.org/security-4.html
x_refsource_CONFIRM
30908
third-party-advisory
x_refsource_SECUNIA
37297
third-party-advisory
x_refsource_SECUNIA
239312
vendor-advisory
x_refsource_SUNALERT
30899
third-party-advisory
x_refsource_SECUNIA
http://www.sec-consult.com/289.html
x_refsource_MISC
ADV-2008-1979
vdb-entry
x_refsource_VUPEN
20090127 CA20090123-01: Cohesion Tomcat Multiple Vulnerabilities (Updated - v1.1)
mailing-list
x_refsource_BUGTRAQ
ADV-2007-1727
vdb-entry
x_refsource_VUPEN
33668
third-party-advisory
x_refsource_SECUNIA
apache-tomcat-url-information-disclosure(27902)
vdb-entry
x_refsource_XF
20090124 CA20090123-01: Cohesion Tomcat Multiple Vulnerabilities
mailing-list
x_refsource_BUGTRAQ
20070509 SEC Consult SA-20070509-0 :: Multiple vulnerabilites in Nokia Intellisync Mobile Suite & Wireless Email Express
mailing-list
x_refsource_BUGTRAQ
ADV-2009-0233
vdb-entry
x_refsource_VUPEN
SUSE-SR:2009:004
vendor-advisory
x_refsource_SUSE
http://support.avaya.com/elmodocs2/security/ASA-2007-206.htm
x_refsource_CONFIRM
25212
third-party-advisory
x_refsource_SECUNIA
20091107 ToutVirtual VirtualIQ Multiple Vulnerabilities
mailing-list
x_refsource_BUGTRAQ
1016576
vdb-entry
x_refsource_SECTRACK
20060721 Directory Listing in Apache Tomcat 5.x.x
mailing-list
x_refsource_FULLDISC
http://tomcat.apache.org/security-5.html
x_refsource_CONFIRM
nokia-tomcat-source-code-disclosure(34183)
vdb-entry
x_refsource_XF
RHSA-2008:0261
vendor-advisory
x_refsource_REDHAT
http://community.ca.com/blogs/casecurityresponseblog/archive/2009/01/23.aspx
x_refsource_CONFIRM
http://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=197540
x_refsource_CONFIRM
[tomcat-dev] 20190319 svn commit: r1855831 [21/30] - in /tomcat/site/trunk: ./ docs/ xdocs/
mailing-list
x_refsource_MLIST
[tomcat-dev] 20190325 svn commit: r1856174 [19/29] - in /tomcat/site/trunk: docs/ xdocs/ xdocs/stylesheets/
mailing-list
x_refsource_MLIST
[tomcat-dev] 20200213 svn commit: r1873980 [24/34] - /tomcat/site/trunk/docs/
mailing-list
x_refsource_MLIST
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now