CVE-2005-4836

NameCVE-2005-4836
DescriptionThe HTTP/1.1 connector in Apache Tomcat 4.1.15 through 4.1.40 does not reject NULL bytes in a URL when allowLinking is configured, which allows remote attackers to read JSP source files and obtain sensitive information.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Notes

[sarge] - tomcat4 <no-dsa> (affects deprecated HTTP/1.1 connector only)

Search for package or bug name: Reporting problems