Jetty provides an HTTP server, HTTP client, and javax.servlet container. This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Eclipse Jetty. A remote unauthenticated attacker can exploit this vulnerability by sending HTTP requests containing illegal characters within multiple fields to the vulnerable server. CVE-2016-6266 - Authenticated remote code execution by exploiting the vulnerability in which $LWCSCTRLEXEC is used directly with untrusted input. Jetty Web server is prone to an information disclosure vulnerability due to improper parsing of HTTP requests. Alias vulnerability allowing access to protected resources within a webapp on Windows. Credit: vulnerability reported by Simon Zuckerbraun of Trend Micro Zero Day Initiative CVE: CVE-2016-4800. Certain versions of Jetty do not correctly sanitize backslash characters in URL requests to the '/cgi-bin' directory. Jetty path traversal. Credit: vulnerability reported by Simon Zuckerbraun of Trend Micro Zero Day Initiative CVE: CVE-2016-4800. Directory traversal vulnerability in the HTTP server in Mort Bay Jetty 5. Authentication is not required to exploit this vulnerability. Exploiting this issue will allow an attacker to view arbitrary files within the context of the webserver. Timeline: 2016-05-03: vulnerability report received 2016-05-06: contacted maintainer 2016-05-11: patch provided by maintainer 2016-05-13: A vulnerability in Jetty Web Server could allow an unauthenticated, remote attacker to access sensitive information. GDS discovered a critical information leakage vulnerability in the Jetty web server that allows an unauthenticated remote attacker to read arbitrary data from previous requests submitted to the server by other users. The specific flaw exists within the way the ContextHandler class restricts access to protected resources. 