← Vulnerability feed

Vulnerability record · CVE-2005-3747 · published 22 November 2005

CVE-2005-3747: Mortbay jetty information exposure vulnerability

MMortbay · Jetty

Unspecified vulnerability in Jetty before 5.1.6 allows remote attackers to obtain source code of JSP pages, possibly involving requests for .jsp files with URL-encoded backslash ("%5C") characters. NOTE: this might be the same issue as CVE-2006-2758.

5.0 CVSS 2.0 Medium EPSS 4.4% · top 9.0% CWE-200 · Information exposure
5.0CVSS 2.0 base score
4.4%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
12References
16 Jun 2026Last modified by NVD

Description

Unspecified vulnerability in Jetty before 5.1.6 allows remote attackers to obtain source code of JSP pages, possibly involving requests for .jsp files with URL-encoded backslash ("%5C") characters. NOTE: this might be the same issue as CVE-2006-2758.

AV:N/AC:L/Au:N/C:P/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2005-3747 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2009-4611Mortbay jetty improper input validation vulnerabilityMort Bay Jetty 6.x through 6.1.22 and 7.0.0 writes backtrace data without sanitizing non-printable characters, which might allow remote attackers to …EPSS 3.2%6.1CVE-2009-5048Mortbay jetty cross-site scripting vulnerabilityCookie Dump Servlet stored XSS vulnerability in jetty though 6.1.20.EPSS 1.6%6.1CVE-2009-5049Mortbay jetty cross-site scripting vulnerabilityWebApp JSP Snoop page XSS in jetty though 6.1.21.EPSS 1.6%5.3CVE-2011-4461Oracle sun storage common array manager vulnerabilityJetty 8.1.0.RC2 and earlier computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which al…EPSS 4.9%5.0CVE-2009-4609Mortbay jetty information exposure vulnerabilityThe Dump Servlet in Mort Bay Jetty 6.x and 7.0.0 allows remote attackers to obtain sensitive information about internal variables and other data via …EPSS 1.8%5.0CVE-2009-1523Mortbay jetty path traversal vulnerabilityDirectory traversal vulnerability in the HTTP server in Mort Bay Jetty 5.1.14, 6.x before 6.1.17, and 7.x through 7.0.0.M2 allows remote attackers to…EPSS 26%4.3CVE-2009-4610Mortbay jetty cross-site scripting vulnerabilityMultiple cross-site scripting (XSS) vulnerabilities in Mort Bay Jetty 6.x and 7.0.0 allow remote attackers to inject arbitrary web script or HTML via…EPSS 3.0%4.3CVE-2009-4612Mortbay jetty cross-site scripting vulnerabilityMultiple cross-site scripting (XSS) vulnerabilities in the WebApp JSP Snoop page in Mort Bay Jetty 6.1.x through 6.1.21 allow remote attackers to inj…EPSS 3.3%

Source: NIST National Vulnerability Database (record CVE-2005-3747), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.