CVE-2009-1523
28Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 26%
from disclosure to weapon927 days
Published on NVDMay 5
1st PoC+927d
exploitation probability
26%top 2% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
Directory traversal vulnerability in the HTTP server in Mort Bay Jetty 5.1.14, 6.x before 6.1.17, and 7.x through 7.0.0.M2 allows remote attackers to access arbitrary files via directory traversal sequences in the URI.
Affected products
n/a · n/apublic PoCs found — 2✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/36318exploitdbwww.exploit-db.com/exploits/18138unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02282388http://jira.codehaus.org/browse/JETTY-1004https://bugzilla.redhat.com/show_bug.cgi?id=499867http://secunia.com/advisories/34975http://secunia.com/advisories/35143http://secunia.com/advisories/35225http://secunia.com/advisories/35776http://secunia.com/advisories/40553https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01257.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-May/msg01259.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-May/msg01262.htmlhttp://www.kb.cert.org/vuls/id/402580