>> Jetty Slash Character Handling Remote Information Disclosure Issue
Title : Jetty Slash Character Handling Remote Information Disclosure Issue VUPEN ID : VUPEN/ADV-2008-0079 CVE ID : GENERIC-MAP-NOMATCH
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-01-09
Technical Description
A vulnerability has been identified in Jetty, which could be exploited by remote attackers to disclose sensitive information. This issue is caused by an error when handling URLs with multiple "/" characters, which could be exploited by remote attackers to bypass security restrictions and view hidden or private files and directories.