Directory traversal vulnerability in Edit.jsp in JSPWiki 2.4.104 and 2.5.139 allows remote attackers to include and execute arbitrary local .jsp files, and obtain sensitive information, via a .. (dot dot) in the editor parameter.
| Software | From | Fixed in |
|---|---|---|
| jspwiki / jspwiki | 2.5.139_beta | 2.5.139_beta.x |
| jspwiki / jspwiki | 2.4.104 | 2.4.104.x |
| jspwiki / jspwiki | 2.5.139 | 2.5.139.x |