CVE-2002-1148

Tomcat <4.1.10 - Info Disclosure

Title source: llm

Description

The default servlet (org.apache.catalina.servlets.DefaultServlet) in Tomcat 4.0.4 and 4.1.10 and earlier allows remote attackers to read source code for server files via a direct request to the servlet.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Rossen Raykov · textremoteunix
https://www.exploit-db.com/exploits/21853

Scores

EPSS 0.6727
EPSS Percentile 98.6%

Details

Status published
Products (20)
apache/tomcat 3.0
apache/tomcat 3.1
apache/tomcat 3.1.1
apache/tomcat 3.2
apache/tomcat 3.2.1
apache/tomcat 3.2.2 beta2
apache/tomcat 3.2.3
apache/tomcat 3.2.4
apache/tomcat 3.3
apache/tomcat 3.3.1
... and 10 more
Published Oct 11, 2002
Tracked Since Feb 18, 2026