Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2002-2007
Description:The default installations of Apache Tomcat 3.2.3 and 3.2.4 allows remote attackers to obtain sensitive system information such as directory listings and web root path, via erroneous HTTP requests for Java Server Pages (JSP) in the (1) test/jsp, (2) samples/jsp and (3) examples/jsp directories, or the (4) test/realPath.jsp servlet, which leaks pathnames in error messages.
Test IDs: 1.3.6.1.4.1.25623.1.0.12123  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2002-2007
BugTraq ID: 4876
http://www.securityfocus.com/bid/4876
BugTraq ID: 4877
http://www.securityfocus.com/bid/4877
BugTraq ID: 4878
http://www.securityfocus.com/bid/4878
Bugtraq: 20020529 Vulnerability in Apache Tomcat v3.23 & v3.24 (Google Search)
http://cert.uni-stuttgart.de/archive/bugtraq/2002/05/msg00272.html
Bugtraq: 20020529 Vulnerability in Apache Tomcat v3.23 & v3.24 (part 2) (Google Search)
http://cert.uni-stuttgart.de/archive/bugtraq/2002/05/msg00275.html
CERT/CC vulnerability note: VU#116963
http://www.kb.cert.org/vuls/id/116963
http://www.procheckup.com/security_info/vuln_pr0205.html
http://www.procheckup.com/security_info/vuln_pr0206.html
http://www.procheckup.com/security_info/vuln_pr0207.html
XForce ISS Database: tomcat-sample-reveal-path(9208)
http://www.iss.net/security_center/static/9208.php




© 1998-2025 E-Soft Inc. All rights reserved.