Exploitation Summary
EIP tracks 3 public exploits for CVE-2016-9177. PoCs published by dawetmaster, andikahilmy, shoucheng3.
AI-analyzed exploit summary This repository appears to be a fork of the Spark Java web framework at a vulnerable commit (fe3ffdc) but does not contain any exploit code or technical analysis of CVE-2016-9177. It includes only the framework's source code and examples.
Description
Directory traversal vulnerability in Spark 2.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the URI.
Exploits (3)
This repository appears to be a fork of the Spark Java web framework at a vulnerable commit (fe3ffdc) but does not contain any exploit code or technical analysis of CVE-2016-9177. It includes only the framework's source code and examples.
This repository appears to be a fork of the Spark Java web framework at a vulnerable commit (fe3ffdc) but does not contain any exploit code or technical analysis of CVE-2016-9177. It includes only the framework's source code and examples.
This repository contains the Spark Java web framework source code, including documentation and examples. It does not contain exploit code but provides technical context for CVE-2016-9177, a directory traversal vulnerability in Spark. The README includes usage examples and API documentation.
References (4)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N