← back
CVE-2006-3835

CVE-2006-3835

35Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendepss 46%
from disclosure to weapon0 days
Published on NVDJul 25
1st PoCJul 21
exploitation probability
46%top 1% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Apache Tomcat 5 before 5.5.17 allows remote attackers to list directories via a semicolon (;) preceding a filename with a mapped extension, as demonstrated by URLs ending with /;index.jsp and /;help.do.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.