CVE-2008-2938
Apache Tomcat < 4.1.37 - Path Traversal
Title source: ruleDescription
Directory traversal vulnerability in Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16, when allowLinking and UTF-8 are enabled, allows remote attackers to read arbitrary files via encoded directory traversal sequences in the URI, a different vulnerability than CVE-2008-2370. NOTE: versions earlier than 6.0.18 were reported affected, but the vendor advisory lists 6.0.16 as the last affected version.
Exploits (5)
metasploit
WORKING POC
by aushack · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/admin/http/trendmicro_dlp_traversal.rb
exploitdb
WORKING POC
VERIFIED
by Simon Ryeo · textremotemultiple
https://www.exploit-db.com/exploits/6229
metasploit
WORKING POC
by aushack, guerrino <ruggine> di massa · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/admin/http/tomcat_utf8_traversal.rb
References (43)
... and 23 more
Scores
EPSS
0.9305
EPSS Percentile
99.8%
Classification
CWE
CWE-22
Status
draft
Affected Products (2)
apache/tomcat
< 4.1.37
org.apache.tomcat/tomcat
< 4.1.39Maven
Timeline
Published
Aug 13, 2008
Tracked Since
Feb 18, 2026