Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Apache Tomcat 4.0.1 allows remote attackers to obtain the web root path via HTTP requests for JSP files preceded by (1) +/, (2) >/, (3) </, and (4) %20/, which leaks the pathname in an error message.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Apache Tomcat存在路径泄露漏洞
Vulnerability Description
Apache Tomcat是一款免费的支持JSP实现的WEB服务程序。Apache Tomcat对特殊URL请求处理存在漏洞,可导致系统敏感信息泄露。攻击者可以提交包含特殊畸形的URL给Apache Tomcat服务器,可导致服务程序返回包含Web ROOT绝对路径的信息给攻击者。攻击者可以根据这些敏感信息对系统进一步进行攻击。
CVSS Information
N/A
Vulnerability Type
N/A