PoC Index

CVE-2010-3863

MEDIUM 5.0EPSS 54.5%

Apache Shiro before 1.1.0, and JSecurity 0.9.x, does not canonicalize URI paths before comparing them to entries in the shiro.ini file, which allows remote attackers to bypass intended access restrictions via a crafted request, as demonstrated by the /./account/index.jsp URI.

CVSS v2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS
54.52% chance of exploitation in the next 30 days, 99th percentile
Nuclei
unknown
Published
2010-11-05
Updated
2024-08-07

Proof-of-concept exploits (1)

Nuclei templates (1)

ExploitDB entries (1)

Vulhub environments (1)

References

Related