VendorsApachetomcat4.1.40
Vulnerabilities

Apache Tomcat 4.1.40

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1CVEs
CVE-2005-4836
The HTTP/1.1 connector in Apache Tomcat 4.1.15 through 4.1.40 does not reject NULL bytes in a URL when allowLinking is configured, which allows remote attackers to read JSP source files and obtain sensitive information.
Published 2007-05-09 · Modified
7.8EPSS 0.035