Loading
mod_jk in Apache Tomcat JK Web Server Connector 1.2.x before 1.2.23 decodes request URLs within the Apache HTTP Server before passing the URL to Tomcat, which allows remote attackers to access protected pages via a crafted prefix JkMount, possibly involving double-encoded .. (dot dot) sequences and directory traversal, a related issue to CVE-2007-0450.
Use CWE-22, Apache vendor hub and Tomcat Jk Web Server Connector product page to widen CVE-2007-1860 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2007-0774 for nearby disclosures in the same product family.