peter bassill · operator
$ cve CVE-2011-4367 JSON

CVE-2011-4367 EXPLOIT

5.0
MEDIUM · CVSS 2.0 · EPSS 33.7% (pctl 98)

Patch early

A public exploit exists.

Description

Multiple directory traversal vulnerabilities in MyFaces JavaServer Faces (JSF) in Apache MyFaces Core 2.0.x before 2.0.12 and 2.1.x before 2.1.6 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) ln parameter to faces/javax.faces.resource/web.xml or (2) the PATH_INFO to faces/javax.faces.resource/.

Scoring

CVSS5.0 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS33.75% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-22
On CISA KEVno
Public exploityes
Published2014-06-19
Last modified2026-06-16

Affected (1)

VendorProduct
apachemyfaces

Public exploits

SourceTitleDate
exploit-dbApache MyFaces - 'ln' Information Disclosure2012-02-09

References

→ the Explorer  ·  watch your stack  ·  NVD