CVE-2006-3835

EPSS 51.5%

Apache Tomcat Reveals Directories

Published: 5/1/2022Modified: 4/4/2025

Description

Apache Tomcat 5 before 5.5.17 allows remote attackers to list directories via a semicolon (`;`) preceding a filename with a mapped extension, as demonstrated by URLs ending with `/;index.jsp` and `/;help.do`.

Affected packages (1)

References (27)