Lucene search

K
cveRedhatCVE-2007-1358
HistoryMay 10, 2007 - 12:19 a.m.

CVE-2007-1358

2007-05-1000:19:00
CWE-79
redhat
web.nvd.nist.gov
61
cve-2007-1358
xss
apache tomcat
vulnerability
nvd

CVSS2

2.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:H/Au:N/C:N/I:P/A:N

AI Score

7.6

Confidence

High

EPSS

0.729

Percentile

98.1%

Cross-site scripting (XSS) vulnerability in certain applications using Apache Tomcat 4.0.0 through 4.0.6 and 4.1.0 through 4.1.34 allows remote attackers to inject arbitrary web script or HTML via crafted “Accept-Language headers that do not conform to RFC 2616”.

Affected configurations

Nvd
Node
apachetomcatRange4.1.31
OR
apachetomcatMatch4.0.0
OR
apachetomcatMatch4.0.1
OR
apachetomcatMatch4.0.2
OR
apachetomcatMatch4.0.3
OR
apachetomcatMatch4.0.4
OR
apachetomcatMatch4.0.5
OR
apachetomcatMatch4.0.6
OR
apachetomcatMatch4.1.0
VendorProductVersionCPE
apachetomcat*cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*
apachetomcat4.0.0cpe:2.3:a:apache:tomcat:4.0.0:*:*:*:*:*:*:*
apachetomcat4.0.1cpe:2.3:a:apache:tomcat:4.0.1:*:*:*:*:*:*:*
apachetomcat4.0.2cpe:2.3:a:apache:tomcat:4.0.2:*:*:*:*:*:*:*
apachetomcat4.0.3cpe:2.3:a:apache:tomcat:4.0.3:*:*:*:*:*:*:*
apachetomcat4.0.4cpe:2.3:a:apache:tomcat:4.0.4:*:*:*:*:*:*:*
apachetomcat4.0.5cpe:2.3:a:apache:tomcat:4.0.5:*:*:*:*:*:*:*
apachetomcat4.0.6cpe:2.3:a:apache:tomcat:4.0.6:*:*:*:*:*:*:*
apachetomcat4.1.0cpe:2.3:a:apache:tomcat:4.1.0:*:*:*:*:*:*:*

References

CVSS2

2.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:H/Au:N/C:N/I:P/A:N

AI Score

7.6

Confidence

High

EPSS

0.729

Percentile

98.1%