Multiple cross-site scripting (XSS) vulnerabilities in the (1) examples and (2) ROOT web applications for Jakarta Tomcat 3.x through 3.3.1a allow remote attackers to insert arbitrary web script or HTML.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.636
EPSS Ranking 98.3%