{"id":"CVE-2016-0709","aliases":[],"url":"https://o3.security/vulnerability/CVE-2016-0709","summary":"Directory traversal vulnerability in the Import/Export function in the Portal Site Manager in Apache Jetspeed before 2.3.1 allows remote authenticated administrators to write to arbitrary…","details":"Directory traversal vulnerability in the Import/Export function in the Portal Site Manager in Apache Jetspeed before 2.3.1 allows remote authenticated administrators to write to arbitrary files, and consequently execute arbitrary code, via a .. (dot dot) in a ZIP archive entry, as demonstrated by \"../../webapps/x.jsp.\"","published":"2016-04-11T14:59:01.677","modified":"2026-06-17T00:38:04.140","cvss":{"score":7.2,"severity":"HIGH","vector":"CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":5,"affectedPackages":[],"fix":null,"references":[{"type":"EXPLOIT","url":"http://haxx.ml/post/140552592371/remote-code-execution-in-apache-jetspeed-230-and"},{"type":"EXPLOIT","url":"http://packetstormsecurity.com/files/136489/Apache-Jetspeed-Arbitrary-File-Upload.html"},{"type":"WEB","url":"http://www.rapid7.com/db/modules/exploit/multi/http/apache_jetspeed_file_upload"},{"type":"WEB","url":"https://mail-archives.apache.org/mod_mbox/portals-jetspeed-user/201603.mbox/%3C281D02D0-6A03-4421-9D86-E73B001C8677%40bluesunrise.com%3E"},{"type":"ADVISORY","url":"https://portals.apache.org/jetspeed-2/security-reports.html#CVE-2016-0709"},{"type":"EXPLOIT","url":"https://www.exploit-db.com/exploits/39643/"},{"type":"EXPLOIT","url":"http://haxx.ml/post/140552592371/remote-code-execution-in-apache-jetspeed-230-and"},{"type":"EXPLOIT","url":"http://packetstormsecurity.com/files/136489/Apache-Jetspeed-Arbitrary-File-Upload.html"},{"type":"WEB","url":"http://www.rapid7.com/db/modules/exploit/multi/http/apache_jetspeed_file_upload"},{"type":"WEB","url":"https://mail-archives.apache.org/mod_mbox/portals-jetspeed-user/201603.mbox/%3C281D02D0-6A03-4421-9D86-E73B001C8677%40bluesunrise.com%3E"},{"type":"ADVISORY","url":"https://portals.apache.org/jetspeed-2/security-reports.html#CVE-2016-0709"},{"type":"EXPLOIT","url":"https://www.exploit-db.com/exploits/39643/"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-06-17T00:38:04.140"}}