Show filters
17 Total Results
Displaying 11-17 of 17
Sort by:
Attacker Value
Unknown
CVE-2003-0044
Disclosure Date: February 07, 2003 (last updated February 22, 2025)
Multiple cross-site scripting (XSS) vulnerabilities in the (1) examples and (2) ROOT web applications for Jakarta Tomcat 3.x through 3.3.1a allow remote attackers to insert arbitrary web script or HTML.
0
Attacker Value
Unknown
CVE-2003-0042
Disclosure Date: February 07, 2003 (last updated February 22, 2025)
Jakarta Tomcat before 3.3.1a, when used with JDK 1.3.1 or earlier, allows remote attackers to list directories even with an index.html or other file present, or obtain unprocessed source code for a JSP file, via a URL containing a null character.
0
Attacker Value
Unknown
CVE-2003-0045
Disclosure Date: February 07, 2003 (last updated February 22, 2025)
Jakarta Tomcat before 3.3.1a on certain Windows systems may allow remote attackers to cause a denial of service (thread hang and resource consumption) via a request for a JSP page containing an MS-DOS device name, such as aux.jsp.
Attacker Value
Unknown
CVE-2003-0043
Disclosure Date: February 07, 2003 (last updated February 22, 2025)
Jakarta Tomcat before 3.3.1a, when used with JDK 1.3.1 or earlier, uses trusted privileges when processing the web.xml file, which could allow remote attackers to read portions of some files through the web.xml file.
0
Attacker Value
Unknown
CVE-2002-1895
Disclosure Date: December 31, 2002 (last updated February 22, 2025)
The servlet engine in Jakarta Apache Tomcat 3.3 and 4.0.4, when using IIS and the ajp1.3 connector, allows remote attackers to cause a denial of service (crash) via a large number of HTTP GET requests for an MS-DOS device such as AUX, LPT1, CON, or PRN.
0
Attacker Value
Unknown
CVE-2002-2006
Disclosure Date: December 31, 2002 (last updated February 22, 2025)
The default installation of Apache Tomcat 4.0 through 4.1 and 3.0 through 3.3.1 allows remote attackers to obtain the installation path and other sensitive system information via the (1) SnoopServlet or (2) TroubleShooter example servlets.
0
Attacker Value
Unknown
CVE-2002-1148
Disclosure Date: October 11, 2002 (last updated February 22, 2025)
The default servlet (org.apache.catalina.servlets.DefaultServlet) in Tomcat 4.0.4 and 4.1.10 and earlier allows remote attackers to read source code for server files via a direct request to the servlet.
0