cve/2002/CVE-2002-1895.md
2025-09-29 21:09:30 +02:00

710 B

CVE-2002-1895

Description

The servlet engine in Jakarta Apache Tomcat 3.3 and 4.0.4, when using IIS and the ajp1.3 connector, allows remote attackers to cause a denial of service (crash) via a large number of HTTP GET requests for an MS-DOS device such as AUX, LPT1, CON, or PRN.

POC

Reference

No PoCs from references.

Github