Description
Apache Tomcat 4.0.3, when running on Windows, allows remote attackers to obtain sensitive information via a request for a file that contains an MS-DOS device name such as lpt9, which leaks the pathname in an error message, as demonstrated by lpt9.xtp using Nikto.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-x89r-2wjq-mj7x | Apache Tomcat Discloses MS-DOS Pathname |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-07T23:53:28.661Z
Reserved: 2006-02-01T00:00:00.000Z
Link: CVE-2005-4703
No data.
Status : Deferred
Published: 2005-12-31T05:00:00.000
Modified: 2025-04-03T01:03:51.193
Link: CVE-2005-4703
No data.
OpenCVE Enrichment
No data.
Weaknesses
Github GHSA