Description
Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16, when a RequestDispatcher is used, performs path normalization before removing the query string from the URI, which allows remote attackers to conduct directory traversal attacks and read arbitrary files via a .. (dot dot) in a request parameter.
Remediation
References
Related Vulnerabilities
WordPress 4.9.x Multiple Vulnerabilities (4.9 - 4.9.23)
Drupal Other Vulnerability (CVE-2008-3661)
MyBB Permissions, Privileges, and Access Controls Vulnerability (CVE-2010-4624)
PHP Improper Input Validation Vulnerability (CVE-2016-4072)
WordPress Plugin FV Flowplayer Video Player Cross-Site Scripting (7.4.37.727)