← Back

CVE-2008-5518

nvd nist
Published: Apr 17, 2009Modified: Apr 23, 2026

JSON object

Loading...
9.4
Vector
AV:N/AC:L/Au:N/C:C/I:C/A:N
Exploitability: 10.0 / Impact: 9.2
Source: NVD

Description

Multiple directory traversal vulnerabilities in the web administration console in Apache Geronimo Application Server 2.1 through 2.1.3 on Windows allow remote attackers to upload files to arbitrary directories via directory traversal sequences in the (1) group, (2) artifact, (3) version, or (4) fileType parameter to console/portal//Services/Repository (aka the Services/Repository portlet); the (5) createDB parameter to console/portal/Embedded DB/DB Manager (aka the Embedded DB/DB Manager portlet); or the (6) filename parameter to the createKeystore script in the Security/Keystores portlet.

Affected (4)

Products: Apache: Geronimo
1 product
Geronimo
Configuration A
4 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Apache
Version 2.1.1
Version 2.1.2
Version 2.1.3
Version 2.1
Running on/withPlatform Versions
Microsoft
Windows
All versions

References (22)

Source: secalert@redhat.com
Exploit
Source: secalert@redhat.com
PatchVendor Advisory
Source: secalert@redhat.com
Source: secalert@redhat.com
Exploit
Source: secalert@redhat.com
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.