Sploitus

CVE-2010-3863

3 known exploits for CVE-2010-3863

Apache Shiro before 1.1.0, and JSecurity 0.9.x, does not canonicalize URI paths before comparing them to entries in the shiro.ini file, which allows remote attackers to bypass intended access restrictions via a crafted request, as demonstrated by the /./account/index.jsp URI.

Affected products
Apache Shiro, Security
Apache Shiro
≤ 1.0.0
Jsecurity
= 0.9.0
Fix
Available
CVSS 2.0
5.0 MEDIUM
EPSS
54.5% (99th percentile)
Weakness
CWE-22
NVD status
Modified
Published
2010-11-05
CVE-2010-3863 at NVD
Authoritative description, scoring and affected products

3 known exploits for CVE-2010-3863

Proof-of-concept code and exploit modules indexed by Sploitus