CVE-2002-1178

Jetty HTTP Server < 4.1.0 - Directory Traversal via CGIServlet

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2002-1178. PoCs published by Matt Moore.

AI-analyzed exploit summary This exploit leverages a directory traversal vulnerability in Jetty's CGIServlet to execute arbitrary commands on Windows systems. The attacker can traverse directories and execute system binaries like notepad.exe.

Description

Directory traversal vulnerability in the CGIServlet for Jetty HTTP server before 4.1.0 allows remote attackers to execute arbitrary commands via ..\ (dot-dot backslash) sequences in an HTTP request to the cgi-bin directory.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Matt Moore · textwebappscgi
https://www.exploit-db.com/exploits/21895

This exploit leverages a directory traversal vulnerability in Jetty's CGIServlet to execute arbitrary commands on Windows systems. The attacker can traverse directories and execute system binaries like notepad.exe.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Jetty versions for Microsoft Windows prior to 4.1.0
No auth needed
Prerequisites: Jetty server running on Windows with vulnerable CGIServlet · Network access to the target server
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Vendor Advisory vdb-entry x_refsource_xf
http://www.iss.net/security_center/static/10246.php
Vendor Advisory x_refsource_confirm
http://groups.yahoo.com/group/jetty-announce/message/45
Exploit, Patch, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/5852
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=103358725813039&w=2

Scores

EPSS 0.0945
EPSS Percentile 94.8%

Details

Status published
Products (1)
jetty/jetty_http_server < 4.1.0
Published Oct 11, 2002
Tracked Since Feb 18, 2026