🔧 AI Nachrichten Context Engineering: The Missing Piece in Agentic Systems(17.09.2026 um 15:00 Uhr)
🔧 ProgrammierungStop Overfeeding Your AI Agent's Context Window(17.09.2026 um 16:00 Uhr)
🔧 ProgrammierungHow I created a Claude plugin to Create Demo Videos(17.09.2026 um 16:26 Uhr)
🔧 ProgrammierungMeasure Your Agent's pass^k Before You Let It Run Overnight(17.09.2026 um 16:28 Uhr)
🔧 ProgrammierungCustom Actions in Attractive.js: one interface, from small to big(17.09.2026 um 16:30 Uhr)
🔧 ProgrammierungWhat Is a Token? The Concept That Unlocks Everything About LLMs(17.09.2026 um 16:30 Uhr)
🔧 AI Nachrichten Context Engineering: The Missing Piece in Agentic Systems(17.09.2026 um 15:00 Uhr)
🔧 ProgrammierungStop Overfeeding Your AI Agent's Context Window(17.09.2026 um 16:00 Uhr)
🔧 ProgrammierungHow I created a Claude plugin to Create Demo Videos(17.09.2026 um 16:26 Uhr)
🔧 ProgrammierungMeasure Your Agent's pass^k Before You Let It Run Overnight(17.09.2026 um 16:28 Uhr)
🔧 ProgrammierungCustom Actions in Attractive.js: one interface, from small to big(17.09.2026 um 16:30 Uhr)
🔧 ProgrammierungWhat Is a Token? The Concept That Unlocks Everything About LLMs(17.09.2026 um 16:30 Uhr)
🕵️ Sicherheitslücken 🕛 vor 9 Jahren 2 Min Lesezeit
0

Spark Sparkjava Framework bis 2.5 Directory Traversal

↗ Quelle (vuldb.com)
🗣️ Stimme:
📑 Inhaltsübersicht

Eine Schwachstelle wurde in Spark Sparkjava Framework bis 2.5 gefunden. Sie wurde als kritisch eingestuft. Es geht hierbei um eine unbekannte Funktion. Dank der Manipulation mit der Eingabe /..\..\spark\Spark.class kann eine Directory Traversal-Schwachstelle ausgenutzt werden. Mit Auswirkungen muss man rechnen für die Vertraulichkeit.

Die Schwachstelle wurde am 03.11.2016 durch aj als Sparkjava Framework - Arbitrary File Read Vulnerability in Form eines ungeprüften Mailinglist Posts (Full-Disclosure) veröffentlicht. Auf geschehen.

Das Advisory stellt fest:

If you need a workaround, don't use Spark to serve static files and move them to another web server.

CVSSv3

Base Score: 5.3
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:U/RC:R
Temp Score: 4.3 (CVSS2#E:POC/RL:U/RC:UR)


  • Aktuelle Preisschätzung: $0-$1k (0-day) / $0-$1k (Heute)

    Gegenmassnahmen

    Empfehlung: keine Massnahme bekannt
    Status: Nicht verfügbar
    0-Day Time: 0 Tage seit gefunden
    Exploit Delay Time: 0 Tage seit bekannt

    Timeline

    03.11.2016
    03.11.2016

    Quellen

    Advisory: Sparkjava Framework - Arbitrary File Read Vulnerability
    Person: aj
    Status: Ungeprüft

    Eintrag

    Erstellt: 03.11.2016
    Eintrag: 78.3% komplett
    Vollständiger Original-Artikel
    Den kompletten Beitrag mit allen Details direkt auf vuldb.com lesen.
    ↗ Original-Artikel auf vuldb.com lesen
  • Wie bewertest du diesen Beitrag?
    1 Klick Feedback
    Teilen mit Netzwerk & Team:

    Community-Analysen & Experten-Meinungen 0

    Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
    Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf Eigene Analyse verfassen“!
    Community Pulse: Relevanz-Einschätzung
    1 Klick Experten-Votum
    🔴 Akute Relevanz 0%
    🟡 In Evaluierung 0%
    🟢 Keine Auswirkung 0%
    Spannende Innovation 0%
    Verwandte Story-Cluster & Quellen (Vektor-KI)
    Port 8095 Engine
    2 Quellen
    CVE-2026-76460 | Cisco Identity Services Engine Software API improper authentication
    1 Quelle
    Microsoft confirms it accidentally broke copy and paste in Excel with a major security update you shouldn’t remove
    1 Quelle
    CVE-2026-69116 | xpf0000 FlyEnv up to 4.17.x Html Sanitization injection