CVE-2003-0042
medium · 5Jakarta Tomcat before 3.3.1a, when used with JDK 1.3.1 or earlier, allows remote attackers to list directories even with an index.html or other file present, or obtain unprocessed source code for a JSP file, via a URL containing a null character.
5
CVSS
46.0%
EPSS (exploit prob.)
99th
EPSS percentile
2003-02-07
Published
AV:N/AC:L/Au:N/C:P/I:N/A:N
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| apache | tomcat | 3.0 |
| apache | tomcat | 3.1 |
| apache | tomcat | 3.1.1 |
| apache | tomcat | 3.2 |
| apache | tomcat | 3.2.1 |
| apache | tomcat | 3.2.3 |
| apache | tomcat | 3.2.4 |
| apache | tomcat | 3.3 |
| apache | tomcat | 3.3.1 |
Check a specific version with /api/v1/cve/match.
References
- http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/
- http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/RELEASE-NOTES-3.3.1a.txt
- http://marc.info/?l=bugtraq&m=104394568616290&w=2
- http://secunia.com/advisories/7972
- http://secunia.com/advisories/7977
- http://www.ciac.org/ciac/bulletins/n-060.shtml
- http://www.debian.org/security/2003/dsa-246
- http://www.securityfocus.com/advisories/5111
- http://www.securityfocus.com/bid/6721
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11194
- http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/
- http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/RELEASE-NOTES-3.3.1a.txt
- http://marc.info/?l=bugtraq&m=104394568616290&w=2
- http://secunia.com/advisories/7972
- http://secunia.com/advisories/7977
- http://www.ciac.org/ciac/bulletins/n-060.shtml
- http://www.debian.org/security/2003/dsa-246
- http://www.securityfocus.com/advisories/5111
- http://www.securityfocus.com/bid/6721
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11194
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2003-0042