Apache Tomcat 5 before 5.5.17 allows remote attackers to list directories via a semicolon (;) preceding a filename with a mapped extension, as demonstrated by URLs ending with /;index.jsp and /;help.do.
Get an AI-powered plain-language explanation of this vulnerability and remediation steps.
Login to generate AI explanation60 reference(s) from NVD