Back

CVE-2002-1567

Cross-site scripting (XSS) vulnerability in Apache Tomcat 4.1 allows remote attackers to execute arbitrary web script and steal cookies via a URL with encoded newlines followed by a request to a .jsp file whose name contains the script.

Published: Oct 6, 2003 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (1)

Vendor Product Version
apache tomcat 4.1.0

GitHub Security Advisory GHSA-86fp-jgwm-wgj5

Apache Tomcat XSS Vulnerability

maven org.apache.tomcat:tomcat >= 4.1.0, < 4.1.29 Fixed: 4.1.29

Risk Scores

CVSS Score 6.8 / 10
EPSS Score 27.08%

Top 2% most likely to be exploited

Threat Score 35.3 / 100

Data Sources

NVD EPSS GitHub