
We found results for “”
CVE-2012-1089
Good to know:


Date: March 23, 2012
Directory traversal vulnerability in Apache Wicket 1.4.x before 1.4.20 and 1.5.x before 1.5.5 allows remote attackers to read arbitrary web-application files via a relative pathname in a URL for a Wicket resource that corresponds to a null package.
Language: Java
Severity Score
Related Resources (5)
Severity Score
Weakness Type (CWE)
Path Traversal
CWE-22Top Fix

Upgrade Version
Upgrade to version org.apache.wicket:wicket:1.4.20;org.apache.wicket:wicket-core:1.5.5
CVSS v2
Base Score: |
|
---|---|
Access Vector (AV): | NETWORK |
Access Complexity (AC): | LOW |
Authentication (AU): | NONE |
Confidentiality (C): | PARTIAL |
Integrity (I): | NONE |
Availability (A): | NONE |
Additional information: |