Back

MEDIUM

tomcat directory listing issue

Published Jul 25, 2006

Description

Apache Tomcat 5 before 5.5.17 allows remote attackers to list directories via a semicolon (;) preceding a filename with a mapped extension, as demonstrated by URLs ending with /;index.jsp and /;help.do.

Affected products

Remediation

Red Hat statement

This issue is not a security issue in Tomcat itself, but is caused when directory listings are enabled. Details on how to disable directory listings are available at: http://tomcat.apache.org/faq/misc.html#listing

Metrics

References (44)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jul 25, 2006
Updated Aug 7, 2024
Reserved Jul 24, 2006
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Low
Public date Jul 21, 2006
GHSA-WFJ7-MHR5-PCWQ