Title : Apache Tomcat "UTF-8" Remote Directory Traversal Vulnerability VUPEN ID : VUPEN/ADV-2008-2343 CVE ID : CVE-2008-2938 CWE ID : CWE-22
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-08-12
Technical Description
A vulnerability has been identified in Apache Tomcat, which could be exploited by attackers to gain unauthorized access to arbitrary files on a vulnerable system. This issue is caused by an input validation error when a context is configured with allowLinking="true" and the connector is configured with URIEncoding set tot "UTF-8", which could be exploited to download arbitrary files from an affected server via directory traversal attacks.