Description
Jakarta Tomcat before 3.3.1a, when used with JDK 1.3.1 or earlier, allows remote attackers to list directories even with an index.html or other file present, or obtain unprocessed source code for a JSP file, via a URL containing a null character.
Remediation
References
Related Vulnerabilities
WordPress Plugin ReDi Restaurant Reservation Cross-Site Scripting (21.0307)
WordPress Plugin Sync to Etsy Marketplace from WooCommerce Cross-Site Request Forgery (3.3.1)
WordPress Plugin GenerateBlocks Cross-Site Scripting (1.3.5)
WordPress Plugin Store Locator Plus for WordPress Privilege Escalation (5.5.14)