← All CVEs

CVE-2003-0042

medium · 5

Jakarta Tomcat before 3.3.1a, when used with JDK 1.3.1 or earlier, allows remote attackers to list directories even with an index.html or other file present, or obtain unprocessed source code for a JSP file, via a URL containing a null character.

5
CVSS
46.0%
EPSS (exploit prob.)
99th
EPSS percentile
2003-02-07
Published

AV:N/AC:L/Au:N/C:P/I:N/A:N

Affected products

VendorProductAffected versions
apachetomcat3.0
apachetomcat3.1
apachetomcat3.1.1
apachetomcat3.2
apachetomcat3.2.1
apachetomcat3.2.3
apachetomcat3.2.4
apachetomcat3.3
apachetomcat3.3.1

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2003-0042