Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2000-0760

EPSS 30.44% · P97
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2000-0760

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
The Snoop servlet in Jakarta Tomcat 3.1 and 3.0 under Apache reveals sensitive system information when a remote attacker requests a nonexistent URL with a .snp extension.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Apache Tomcat Snoop Servlet远程信息泄漏漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Apache Apache Tomcat是美国阿帕奇(Apache)软件基金会下属的Jakarta项目的一款轻量级Web应用服务器,它主要用于开发和调试JSP程序,适用于中小型系统。 Tomcat的snoop servlet组件存在一个安全问题,可能会泄漏服务器的敏感信息。 向Tomcat请求一个不存在的以 .snp 为扩展名的文件就会从服务器返回很多对入侵者很有用的信息,包括Web绝对路径,操作系统类型等。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2000-0760

#POC DescriptionSource LinkShenlong Link
1The Snoop servlet in Jakarta Tomcat 3.1 and 3.0 under Apache reveals sensitive system information when a remote attacker requests a nonexistent URL with a .snp extension. https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2000/CVE-2000-0760.yamlPOC Details
2The Snoop servlet is exposed in the Apache Tomcat examples directory. https://github.com/projectdiscovery/nuclei-templates/blob/main/http/misconfiguration/tomcat-snoop-servlet-exposed.yamlPOC Details
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2000-0760

登录查看更多情报信息。

Same Patch Batch · n/a · 2000-09-21 · 48 CVEs total

CVE-2000-0769O'Reilly WebSite Pro写访问漏洞
CVE-2000-0775Robotex Viking 服务器缓冲区溢出漏洞
CVE-2000-0785WircSrv IRC服务器读取任意文件漏洞
CVE-2000-0794IRIX libgl.so缓冲区溢出漏洞
CVE-2000-0798IRIX xfs truncate()权限检查漏洞
CVE-2000-0800SuSE linuxnfs/knfsd rpc.kstatd权限提升漏洞
CVE-2000-0801HP-UX bdf/df缓冲区溢出漏洞
CVE-2000-0802BAIR权限提升漏洞
CVE-2000-0793NortonAntivirus Novell客户端防毒自动保护失效漏洞
CVE-2000-0772Tumbleweed MMS No默认密码漏洞
CVE-2000-0774Bajie Webserver绝对路径泄露漏洞
CVE-2000-0759Apache Tomcat 3.1远程泄露服务器信息漏洞
CVE-2000-0757Aptis Software TotalBill远程命令执行漏洞
CVE-2000-0756Microsoft Outlook Vcard DoS漏洞
CVE-2000-0755HP OpenView Network Node Manager 6.1 Web密码漏洞
CVE-2000-0752FreeBSD端口brouted安装许可漏洞
CVE-2000-0748OpenLDAP 'ud'群组可写漏洞
CVE-2000-0746微软IIS跨站脚本攻击.shtml漏洞
CVE-2000-0736Becky! Internet Mail头缓冲区溢出漏洞
CVE-2000-0735Becky! Internet邮件头缓冲区溢出漏洞

Showing top 20 of 48 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2000-0760

No comments yet


Leave a comment