CVE-2005-3747
23Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 4.4%
from disclosure to weapon2297 days
Published on NVDNov 22
1st PoC+2297d
exploitation probability
4.4%top 10% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Unspecified vulnerability in Jetty before 5.1.6 allows remote attackers to obtain source code of JSP pages, possibly involving requests for .jsp files with URL-encoded backslash ("%5C") characters. NOTE: this might be the same issue as CVE-2006-2758.
Affected products
n/a · n/apublic PoCs found — 1
exploitdbwww.exploit-db.com/exploits/18571unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://secunia.com/advisories/17659http://secunia.com/advisories/22669http://sourceforge.net/project/shownotes.php?release_id=372086&group_id=7322http://www.securityfocus.com/archive/1/450315/100/0/threadedhttp://www.securityfocus.com/bid/15515http://www.vupen.com/english/advisories/2005/2515