Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2002-1895

The servlet engine in Jakarta Apache Tomcat 3.3 and 4.0.4, when using IIS and the ajp1.3 connector, allows remote attackers to cause a denial of service (crash) via a large number of HTTP GET requests for an MS-DOS device such as AUX, LPT1, CON, or PRN.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.028
EPSS Ranking 85.3%
CVSS Severity
CVSS v2 Score 5.0
References
Products affected by CVE-2002-1895
  • Apache » Tomcat » Version: 3.3
    cpe:2.3:a:apache:tomcat:3.3
  • Apache » Tomcat » Version: 4.0.4
    cpe:2.3:a:apache:tomcat:4.0.4


Contact Us

Shodan ® - All rights reserved