Back

CVE-2002-1178

Directory traversal vulnerability in the CGIServlet for Jetty HTTP server before 4.1.0 allows remote attackers to execute arbitrary commands via ..\ (dot-dot backslash) sequences in an HTTP request to the cgi-bin directory.

Published: Oct 11, 2002 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (1)

Vendor Product Version
jetty jetty_http_server *

GitHub Security Advisory GHSA-rrv3-c2mh-pf7x

Directory traversal vulnerability in the CGIServlet for Jetty HTTP server before 4.1.0 allows...

Risk Scores

CVSS Score 5.0 / 10
EPSS Score 9.46%

Top 5% most likely to be exploited

Threat Score 22.8 / 100

Data Sources

NVD EPSS GitHub