Apache Tomcat can be tricked to disclose files, directory listings and unprocessed JSP files. This issue affects Apache Tomcat version 3.3.1 and earlier. Tomcat users should upgrade to version 3.3.1a.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/30766/tomcat-null-byte.txt
Source: https://packetstormsecurity.com/files/30766/tomcat-null-byte.txt.html

