CVE-2000-0760
medium · 6.4A public exploit / detection template exists
Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates →
The Snoop servlet in Jakarta Tomcat 3.1 and 3.0 under Apache reveals sensitive system information when a remote attacker requests a nonexistent URL with a .snp extension.
6.4
CVSS
62.5%
EPSS (exploit prob.)
99th
EPSS percentile
2000-10-20
Published
AV:N/AC:L/Au:N/C:P/I:P/A:N
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| apache | tomcat | 3.0 |
| apache | tomcat | 3.1 |
Check a specific version with /api/v1/cve/match.
References
- http://www.securityfocus.com/bid/1532
- http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D2000-07-15%26msg%3DPine.SUN.3.96.1000719235404.24004A-100000%40grex.cyberspace.org
- http://www.securityfocus.com/bid/1532
- http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D2000-07-15%26msg%3DPine.SUN.3.96.1000719235404.24004A-100000%40grex.cyberspace.org
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2000-0760