CVE-2005-4703

Apache Tomcat 4.0.3 - Info Disclosure

Title source: llm

Description

Apache Tomcat 4.0.3, when running on Windows, allows remote attackers to obtain sensitive information via a request for a file that contains an MS-DOS device name such as lpt9, which leaks the pathname in an error message, as demonstrated by lpt9.xtp using Nikto.

Exploits (1)

exploitdb WORKING POC VERIFIED
by security curmudgeon · textremotemultiple
https://www.exploit-db.com/exploits/31551

Scores

EPSS 0.1835
EPSS Percentile 95.2%

Details

Status published
Products (2)
apache/tomcat 4.0.3
org.apache.tomcat/tomcat 0Maven
Published Dec 31, 2005
Tracked Since Feb 18, 2026