S4E just found an informational finding from [ai] rate limit test scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
CVE

CVE-2007-2449

4.3
CVSS
Description

Multiple cross-site scripting (XSS) vulnerabilities in certain JSP files in the examples web application in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.36, 5.0.0 through 5.0.30, 5.5.0 through 5.5.24, and 6.0.0 through 6.0.13 allow remote attackers to inject arbitrary web script or HTML via the portion of the URI after the ';' character, as demonstrated by a URI containing a "snp/snoop.jsp;" sequence.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Updated Sep 18, 2026View on NVD →
S4E scanner

CVE-2007-2449 Scanner

Detects 'Cross-Site Scripting (XSS)' vulnerability in Apache Tomcat affects v. 4.0.0 through 4.0.6, 4.1.0 through 4.1.36, 5.0.0 through 5.0.30, 5.5.0 through 5.5.24, and 6.0.0 through 6.0.13.

Used 3.5k times · 2 assets checked · url

Monitor this CVE on your assets

S4E maps published CVEs to scanners and forecasts the next disclosure window for your stack.

Create a free account →