Sploitus

CVE-2002-2009

No indexed exploits for CVE-2002-2009 yet

Apache Tomcat 4.0.1 allows remote attackers to obtain the web root path via HTTP requests for JSP files preceded by (1) +/, (2) >/, (3) </, and (4) %20/, which leaks the pathname in an error message.

Affected products
Apache Tomcat
Apache Tomcat
= 4.0.1
Fix
Available
CVSS 2.0
5.0 MEDIUM
EPSS
7.3% (94th percentile)
NVD status
Modified
Published
2005-07-14
CVE-2002-2009 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2002-2009 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2002-2009 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.