CVE-2005-3747

Mortbay Jetty < 5.1.5 - Information Disclosure

Title source: rule

Description

Unspecified vulnerability in Jetty before 5.1.6 allows remote attackers to obtain source code of JSP pages, possibly involving requests for .jsp files with URL-encoded backslash ("%5C") characters. NOTE: this might be the same issue as CVE-2006-2758.

Exploits (1)

exploitdb WORKING POC
webappsphp
https://www.exploit-db.com/exploits/18571

Scores

EPSS 0.1731
EPSS Percentile 94.9%

Classification

CWE
CWE-200
Status draft

Affected Products (50)

mortbay/jetty < 5.1.5
mortbay/jetty
mortbay/jetty
mortbay/jetty
mortbay/jetty
mortbay/jetty
mortbay/jetty
mortbay/jetty
mortbay/jetty
mortbay/jetty
mortbay/jetty
mortbay/jetty
mortbay/jetty
mortbay/jetty
mortbay/jetty
... and 35 more

Timeline

Published Nov 22, 2005
Tracked Since Feb 18, 2026