peter bassill · operator
$ cve CVE-2007-5731 JSON

CVE-2007-5731 EXPLOIT

3.5
LOW · CVSS 2.0 · EPSS 7.1% (pctl 94)

Patch early

A public exploit exists.

Description

Absolute path traversal vulnerability in Apache Jakarta Slide 2.1 and earlier allows remote authenticated users to read arbitrary files via a WebDAV write request that specifies an entity with a SYSTEM tag, a related issue to CVE-2007-5461.

Scoring

CVSS3.5 (LOW, v2.0)
VectorAV:N/AC:M/Au:S/C:P/I:N/A:N
EPSS7.14% — more likely to be exploited than 94% of all CVEs
WeaknessCWE-22
On CISA KEVno
Public exploityes
Published2007-10-30
Last modified2026-06-16

Affected (1)

VendorProduct
apachejakarta slide

Public exploits

SourceTitleDate
exploit-dbJakarta Slide 2.1 RC1 - Remote File Disclosure2007-10-24

References

→ the Explorer  ·  watch your stack  ·  NVD