A vulnerability in Apache's Tomcat allows attackers to utilize a directory traversal vulnerability whenever context.xml or server.xml allows 'allowLinking'and 'URIencoding' as 'UTF-8'.
Vulnerable Systems:
* Apache Tomcat versions prior to 6.0.18
Immune Systems:
* Apache Tomcat version 6.0.18
Exploit:
If your webroot directory has three depth(e.g /usr/local/wwwroot), An attacker can access arbitrary files as below. (Proof-of-concept) http://www.target.com/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/foo/bar