Id:
CVE-2006-2759
Comment
:
jetty 6.0.x (jetty6) beta16 allows remote attackers to read arbitrary script source code via a capital P in the .jsp extension, and probably other mixed case manipulations.
CVSSv2 Score:
5
Access vector:
|
NETWORK
|
Access complexity:
|
LOW
|
Authentication:
|
NONE
|
Confidentiality impact:
|
PARTIAL
|
Integrity impact:
|
NONE
|
Availability impact:
|
NONE
|
CVSSv2 Vector:
AV:N/AC:L/Au:N/C:P/I:N/A:N
References: