← All CVEs

CVE-2008-2370

medium · 5

Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16, when a RequestDispatcher is used, performs path normalization before removing the query string from the URI, which allows remote attackers to conduct directory traversal attacks and read arbitrary files via a .. (dot dot) in a request parameter.

5
CVSS
52.7%
EPSS (exploit prob.)
99th
EPSS percentile
2008-08-04
Published

AV:N/AC:L/Au:N/C:P/I:N/A:N

Weaknesses

CWE-22

Affected products

VendorProductAffected versions
apachetomcat4.1.0
apachetomcat4.1.1
apachetomcat4.1.2
apachetomcat4.1.3
apachetomcat4.1.4
apachetomcat4.1.5
apachetomcat4.1.6
apachetomcat4.1.7
apachetomcat4.1.8
apachetomcat4.1.9
apachetomcat4.1.10
apachetomcat4.1.11
apachetomcat4.1.12
apachetomcat4.1.13
apachetomcat4.1.14
apachetomcat4.1.15
apachetomcat4.1.16
apachetomcat4.1.17
apachetomcat4.1.18
apachetomcat4.1.19
apachetomcat4.1.20
apachetomcat4.1.21
apachetomcat4.1.22
apachetomcat4.1.23
apachetomcat4.1.24
apachetomcat4.1.25
apachetomcat4.1.26
apachetomcat4.1.27
apachetomcat4.1.28
apachetomcat4.1.29
apachetomcat4.1.30
apachetomcat4.1.31
apachetomcat4.1.32
apachetomcat4.1.33
apachetomcat4.1.34
apachetomcat4.1.35
apachetomcat4.1.36
apachetomcat4.1.37
apachetomcat5.5.0
apachetomcat5.5.1

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2008-2370