Show filters
22 Total Results
Displaying 21-22 of 22
Sort by:
Attacker Value
Unknown
CVE-2005-2090
Disclosure Date: July 05, 2005 (last updated February 22, 2025)
Jakarta Tomcat 5.0.19 (Coyote/1.1) and Tomcat 4.1.24 (Coyote/1.0) allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which causes Tomcat to incorrectly handle and forward the body of the request in a way that causes the receiving server to process it as a separate HTTP request, aka "HTTP Request Smuggling."
0
Attacker Value
Unknown
CVE-2002-2272
Disclosure Date: December 31, 2002 (last updated February 22, 2025)
Tomcat 4.0 through 4.1.12, using mod_jk 1.2.1 module on Apache 1.3 through 1.3.27, allows remote attackers to cause a denial of service (desynchronized communications) via an HTTP GET request with a Transfer-Encoding chunked field with invalid values.
0