CVE-2005-3747

Mortbay Jetty < 5.1.5 - Information Disclosure

Title source: rule

Description

Unspecified vulnerability in Jetty before 5.1.6 allows remote attackers to obtain source code of JSP pages, possibly involving requests for .jsp files with URL-encoded backslash ("%5C") characters. NOTE: this might be the same issue as CVE-2006-2758.

Exploits (1)

exploitdb WORKING POC
webappsphp
https://www.exploit-db.com/exploits/18571

Scores

EPSS 0.1941
EPSS Percentile 95.4%

Details

CWE
CWE-200
Status published
Products (41)
mortbay/jetty 1.0
mortbay/jetty 1.0.1
mortbay/jetty 1.1
mortbay/jetty 1.1.1
mortbay/jetty 1.2.0
mortbay/jetty 1.3.0
mortbay/jetty 1.3.1
mortbay/jetty 1.3.2
mortbay/jetty 1.3.3
mortbay/jetty 1.3.4
... and 31 more
Published Nov 22, 2005
Tracked Since Feb 18, 2026