Bullwark Momentum Series JAWS Directory Traversal Vulnerability

Vulnerability

A directory traversal vulnerability has been identified in Bullwark Momentum Series JAWS version 1.0. This vulnerability allows unauthenticated attackers to access sensitive system files by manipulating HTTP request paths. Exploitation involves sending crafted GET requests that include multiple '../' sequences to read files such as /etc/passwd, bypassing the web root directory.

Impact

Exploitation of this vulnerability could lead to unauthorized access to sensitive system files, potentially allowing attackers to gain further insights into the system or application environment.

Reproduction

The vulnerability can be reproduced by sending a GET request that includes a series of '../' sequences in the request path. This request should be directed to the Bullwark Momentum Series JAWS 1.0 web server. The crafted request will traverse directories and access files outside the web root, such as /etc/passwd.

Added: Feb 12, 2026, 11:26 PM
Updated: Feb 12, 2026, 11:26 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
8.7
remediation
0.0
relevance
2.9
threat
6.4
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.