CVE-2002-1148
Tomcat <4.1.10 - Info Disclosure
Title source: llmDescription
The default servlet (org.apache.catalina.servlets.DefaultServlet) in Tomcat 4.0.4 and 4.1.10 and earlier allows remote attackers to read source code for server files via a direct request to the servlet.
Exploits (1)
exploitdb
WRITEUP
VERIFIED
by Rossen Raykov · textremoteunix
https://www.exploit-db.com/exploits/21853
References (10)
Scores
EPSS
0.6727
EPSS Percentile
98.6%
Details
Status
published
Products (20)
apache/tomcat
3.0
apache/tomcat
3.1
apache/tomcat
3.1.1
apache/tomcat
3.2
apache/tomcat
3.2.1
apache/tomcat
3.2.2 beta2
apache/tomcat
3.2.3
apache/tomcat
3.2.4
apache/tomcat
3.3
apache/tomcat
3.3.1
... and 10 more
Published
Oct 11, 2002
Tracked Since
Feb 18, 2026