Lucene search

K
osvGoogleOSV:GHSA-3P86-XGRQ-M6P6
HistoryMay 03, 2022 - 3:25 a.m.

Improper Neutralization of Input During Web Page Generation in Apache Tomcat

2022-05-0303:25:09
Google
osv.dev
16
apache tomcat
multiple xss vulnerabilities
html manager interface
remote attackers
web script or html

EPSS

0.001

Percentile

50.9%

Multiple cross-site scripting (XSS) vulnerabilities in the HTML Manager Interface in Apache Tomcat 5.5 before 5.5.32, 6.0 before 6.0.30, and 7.0 before 7.0.6 allow remote attackers to inject arbitrary web script or HTML, as demonstrated via the display-name tag.

References