Back

CVE-2002-0682

Cross-site scripting vulnerability in Apache Tomcat 4.0.3 allows remote attackers to execute script as other web users via script in a URL with the /servlet/ mapping, which does not filter the script when an exception is thrown by the servlet.

Published: Jul 23, 2002 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (1)

Vendor Product Version
apache tomcat 4.0.3

GitHub Security Advisory GHSA-jjxj-xvcp-cxv8

Cross-site scripting vulnerability in Apache Tomcat 4.0.3 allows remote attackers to execute...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 12.24%

Top 4% most likely to be exploited

Threat Score 33.7 / 100

Data Sources

NVD EPSS GitHub