Title : Apache Tomcat WebDAV Servlet Remote File Disclosure Vulnerability VUPEN ID : VUPEN/ADV-2007-3622 CVE ID : CVE-2007-5461
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-10-25
Technical Description
A vulnerability has been identified in Apache Tomcat, which could be exploited by remote attackers to gain knowledge of sensitive information. This issue is caused by an error in the WebDAV servlet when configured for use with a context and enabled for write, which could be exploited by remote attackers to disclose the contents of arbitary files by sending specially crafted WebDAV requests that specify an entity with a SYSTEM tag.