Lucene search

K
cvelistRedhatCVELIST:CVE-2005-4836
HistoryMay 09, 2007 - 10:00 p.m.

CVE-2005-4836

2007-05-0922:00:00
redhat
www.cve.org

AI Score

7.4

Confidence

High

EPSS

0.001

Percentile

43.5%

The HTTP/1.1 connector in Apache Tomcat 4.1.15 through 4.1.40 does not reject NULL bytes in a URL when allowLinking is configured, which allows remote attackers to read JSP source files and obtain sensitive information.

AI Score

7.4

Confidence

High

EPSS

0.001

Percentile

43.5%

Related for CVELIST:CVE-2005-4836