EIP-2026-119350
PRE-CVEApache Tomcat 4.0.3 - Denial of Service 'Device Name' / Cross-Site Scripting
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-119350. PoCs published by Matt Moore.
AI-analyzed exploit summary The provided text describes a cross-site scripting (XSS) vulnerability in Apache Tomcat 4.0.3 on Windows, where requesting a DOS device file name (e.g., COM2.IMG) with appended JavaScript can trigger an error message containing the malicious script. This is a technical summary of the vulnerability without functional exploit code.
Description
Apache Tomcat 4.0.3 - Denial of Service 'Device Name' / Cross-Site Scripting
Exploits (1)
The provided text describes a cross-site scripting (XSS) vulnerability in Apache Tomcat 4.0.3 on Windows, where requesting a DOS device file name (e.g., COM2.IMG) with appended JavaScript can trigger an error message containing the malicious script. This is a technical summary of the vulnerability without functional exploit code.