>> JBoss Application Server Directory Traversal and Code Execution Vulnerability
Title : JBoss Application Server Directory Traversal and Code Execution Vulnerability VUPEN ID : VUPEN/ADV-2006-4724 CVE ID : CVE-2006-5750
Rated as : Critical
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2006-11-28
Technical Description
A vulnerability has been identified in JBoss Application Server, which could be exploited by remote attackers to compromise a vulnerable server. This issue is due to an input validation error in the "setBaseDir()" method within the "DeploymentFileRepository" class that does not validate user-supplied arguments before being passed to a "store()" or "remove()" method, which could be exploited by a remote unauthenticated attacker who is able to access the console manager to read and write files via a directory traversal, or execute arbitrary commands with the privileges of the application.