CVE-2008-2403

Sun Java ASP Server < 4.0.3 - Path Traversal via MapPath Method

Title source: llm
STIX 2.1

Description

Multiple directory traversal vulnerabilities in unspecified ASP applications in Sun Java Active Server Pages (ASP) Server before 4.0.3 allow remote attackers to read or delete arbitrary files via a .. (dot dot) in the Path parameter to the MapPath method.

References (7)

Core 7
Core References
Patch vendor-advisory x_refsource_sunalert
http://sunsolve.sun.com/search/document.do?assetkey=1-66-238184-1
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/29538
Third Party Advisory third-party-advisory x_refsource_idefense
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=707
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1020188
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/1742/references
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/30523
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/42831

Scores

EPSS 0.0100
EPSS Percentile 77.2%

Details

CWE
CWE-22
Status published
Products (3)
sun/java_asp_server 4.0
sun/java_asp_server 4.0.1
sun/java_asp_server < 4.0.2
Published Jun 04, 2008
Tracked Since Feb 18, 2026