suse · CVE-2006-2758

Quick triage

Priority: medium Published: 2023-04-20 01:47:19 UTC Updated: 2023-07-25 01:59:15 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2006-2758 severity moderate: SUSE including 8 source package names (jetty-http, jetty-io, …), 89 product×package rows across 12 product lines (SUSE Enterprise Storage 7, SUSE Enterprise Storage 7.1, … (12 product lines)): Known Not Affected 89.

Description:

Directory traversal vulnerability in jetty 6.0.x (jetty6) beta16 allows remote attackers to read arbitrary files via a %2e%2e%5c (encoded ../) in the URL. NOTE: this might be the same issue as CVE-2005-3747.

cvelogic Threat Intelligence