CVE-2003-0042

Jakarta Tomcat <3.3.1a - Info Disclosure

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2003-0042. PoCs published by Jouko Pynnönen.

AI-analyzed exploit summary This exploit demonstrates a directory traversal and file disclosure vulnerability in Apache Tomcat when used with JDK 1.3.1 or earlier. It leverages improper handling of null bytes and backslash characters to access restricted files and directories.

Description

Jakarta Tomcat before 3.3.1a, when used with JDK 1.3.1 or earlier, allows remote attackers to list directories even with an index.html or other file present, or obtain unprocessed source code for a JSP file, via a URL containing a null character.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Jouko Pynnönen · textremotelinux
https://www.exploit-db.com/exploits/22205

This exploit demonstrates a directory traversal and file disclosure vulnerability in Apache Tomcat when used with JDK 1.3.1 or earlier. It leverages improper handling of null bytes and backslash characters to access restricted files and directories.

Classification
Working Poc 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Apache Tomcat with JDK 1.3.1 or earlier
No auth needed
Prerequisites: Apache Tomcat with JDK 1.3.1 or earlier · Network access to the target server
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (10)

Core 10
Core References
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/7977
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/7972
Patch, Vendor Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2003/dsa-246
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/6721
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=104394568616290&w=2
Third Party Advisory, VDB Entry vendor-advisory x_refsource_hp
http://www.securityfocus.com/advisories/5111
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/11194
Third Party Advisory, US Government Resource third-party-advisory government-resource x_refsource_ciac
http://www.ciac.org/ciac/bulletins/n-060.shtml

Scores

EPSS 0.5583
EPSS Percentile 98.1%

Details

Status published
Products (10)
apache/tomcat 3.0
apache/tomcat 3.1
apache/tomcat 3.1.1
apache/tomcat 3.2
apache/tomcat 3.2.1
apache/tomcat 3.2.3
apache/tomcat 3.2.4
apache/tomcat 3.3
apache/tomcat 3.3.1
org.apache.tomcat/tomcat 0 - 3.3.1aMaven
Published Feb 07, 2003
Tracked Since Feb 18, 2026