Vulnerabilities > CVE-2001-0917 - Unspecified vulnerability in Apache Tomcat 4.0.1
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN apache
nessus
Summary
Jakarta Tomcat 4.0.1 allows remote attackers to reveal physical path information by requesting a long URL with a .JSP extension.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Nessus
NASL family | Web Servers |
NASL id | TOMCAT_LONG_URL_PATH_DISCLOSE.NASL |
description | The remote Apache Tomcat web server is affected by an information disclosure vulnerability. The full install path of Apache Tomcat can be obtained by sending an HTTP request which contains a long URL. Note that there reportedly is an additional install path disclosure vulnerability in this version of Apache Tomcat; however, Nessus has not explicitly tested for it. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 49701 |
published | 2010-10-01 |
reporter | This script is Copyright (C) 2010-2018 and is owned by Tenable, Inc. or an Affiliate thereof. |
source | https://www.tenable.com/plugins/nessus/49701 |
title | Apache Tomcat Long URL Information Disclosure |
code |
|
References
- http://marc.info/?l=bugtraq&m=100654722925155&w=2
- http://marc.info/?l=bugtraq&m=100654722925155&w=2
- http://marc.info/?l=tomcat-dev&m=100658457507305&w=2
- http://marc.info/?l=tomcat-dev&m=100658457507305&w=2
- https://exchange.xforce.ibmcloud.com/vulnerabilities/7599
- https://exchange.xforce.ibmcloud.com/vulnerabilities/7599
- https://lists.apache.org/thread.html/29dc6c2b625789e70a9c4756b5a327e6547273ff8bde7e0327af48c5%40%3Cdev.tomcat.apache.org%3E
- https://lists.apache.org/thread.html/29dc6c2b625789e70a9c4756b5a327e6547273ff8bde7e0327af48c5%40%3Cdev.tomcat.apache.org%3E
- https://lists.apache.org/thread.html/c62b0e3a7bf23342352a5810c640a94b6db69957c5c19db507004d74%40%3Cdev.tomcat.apache.org%3E
- https://lists.apache.org/thread.html/c62b0e3a7bf23342352a5810c640a94b6db69957c5c19db507004d74%40%3Cdev.tomcat.apache.org%3E
- https://lists.apache.org/thread.html/rb71997f506c6cc8b530dd845c084995a9878098846c7b4eacfae8db3%40%3Cdev.tomcat.apache.org%3E
- https://lists.apache.org/thread.html/rb71997f506c6cc8b530dd845c084995a9878098846c7b4eacfae8db3%40%3Cdev.tomcat.apache.org%3E