Vulnerabilities
Vulnerable Software
Apache:  >> Tomcat  >> 3.0  Security Vulnerabilities
Apache Tomcat before 5.x allows remote attackers to cause a denial of service (application crash) via a crafted AJP12 packet to TCP port 8007.
CVSS Score
5.0
EPSS Score
0.175
Published
2005-05-02
Jakarta Tomcat before 3.3.1a, when used with JDK 1.3.1 or earlier, allows remote attackers to list directories even with an index.html or other file present, or obtain unprocessed source code for a JSP file, via a URL containing a null character.
CVSS Score
5.0
EPSS Score
0.558
Published
2003-02-07
Jakarta Tomcat before 3.3.1a, when used with JDK 1.3.1 or earlier, uses trusted privileges when processing the web.xml file, which could allow remote attackers to read portions of some files through the web.xml file.
CVSS Score
5.0
EPSS Score
0.023
Published
2003-02-07
Multiple cross-site scripting (XSS) vulnerabilities in the (1) examples and (2) ROOT web applications for Jakarta Tomcat 3.x through 3.3.1a allow remote attackers to insert arbitrary web script or HTML.
CVSS Score
6.8
EPSS Score
0.273
Published
2003-02-07
Jakarta Tomcat before 3.3.1a on certain Windows systems may allow remote attackers to cause a denial of service (thread hang and resource consumption) via a request for a JSP page containing an MS-DOS device name, such as aux.jsp.
CVSS Score
5.0
EPSS Score
0.015
Published
2003-02-07
The default installation of Apache Tomcat 4.0 through 4.1 and 3.0 through 3.3.1 allows remote attackers to obtain the installation path and other sensitive system information via the (1) SnoopServlet or (2) TroubleShooter example servlets.
CVSS Score
5.0
EPSS Score
0.324
Published
2002-12-31
The default servlet (org.apache.catalina.servlets.DefaultServlet) in Tomcat 4.0.4 and 4.1.10 and earlier allows remote attackers to read source code for server files via a direct request to the servlet.
CVSS Score
5.0
EPSS Score
0.367
Published
2002-10-11
Apache Tomcat may be started without proper security settings if errors are encountered while reading the web.xml file, which could allow attackers to bypass intended restrictions.
CVSS Score
7.5
EPSS Score
0.015
Published
2002-08-12
Directory traversal vulnerability in source.jsp of Apache Tomcat before 3.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the argument to source.jsp.
CVSS Score
5.0
EPSS Score
0.039
Published
2002-03-22
Apache Software Foundation Tomcat Servlet prior to 3.2.2 allows a remote attacker to read the source code to arbitrary 'jsp' files via a malformed URL request which does not end with an HTTP protocol specification (i.e. HTTP/1.0).
CVSS Score
5.0
EPSS Score
0.218
Published
2001-08-02


Contact Us

Shodan ® - All rights reserved