CVE-2002-1567

Apache Tomcat 4.1 - XSS

Title source: llm

Description

Cross-site scripting (XSS) vulnerability in Apache Tomcat 4.1 allows remote attackers to execute arbitrary web script and steal cookies via a URL with encoded newlines followed by a request to a .jsp file whose name contains the script.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Skinnay · textremoteunix
https://www.exploit-db.com/exploits/21734

Scores

EPSS 0.4166
EPSS Percentile 97.4%

Details

Status published
Products (2)
apache/tomcat 4.1.0
org.apache.tomcat/tomcat 4.1.0 - 4.1.29Maven
Published Oct 06, 2003
Tracked Since Feb 18, 2026