peter bassill · operator
$ cve CVE-2002-2006 JSON

CVE-2002-2006 EXPLOIT

5.0
MEDIUM · CVSS 2.0 · EPSS 30.7% (pctl 98)

Patch early

A public exploit exists.

Description

The default installation of Apache Tomcat 4.0 through 4.1 and 3.0 through 3.3.1 allows remote attackers to obtain the installation path and other sensitive system information via the (1) SnoopServlet or (2) TroubleShooter example servlets.

Scoring

CVSS5.0 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS30.67% — more likely to be exploited than 98% of all CVEs
On CISA KEVno
Public exploityes
Published2002-12-31
Last modified2026-06-16

Affected (1)

VendorProduct
apachetomcat

Public exploits

SourceTitleDate
exploit-dbApache Tomcat 4.0/4.1 - Servlet Full Path Disclosure2002-04-23

References

→ the Explorer  ·  watch your stack  ·  NVD