5
CVSSv2

CVE-2005-4703

Published: 31/12/2005 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Apache Tomcat 4.0.3, when running on Windows, allows remote malicious users to obtain sensitive information via a request for a file that contains an MS-DOS device name such as lpt9, which leaks the pathname in an error message, as demonstrated by lpt9.xtp using Nikto.

Vulnerable Product Search on Vulmon Subscribe to Product

apache tomcat 4.0.3

Exploits

source: wwwsecurityfocuscom/bid/28484/info Apache Tomcat is prone to an information-disclosure vulnerability when handling requests that contain MS-DOS device names Attackers can leverage this issue to obtain potentially sensitive data that could aid in other attacks Tomcat 403 running on Windows is vulnerable; other versions may al ...