Lucene search

K
osvGoogleOSV:GHSA-PM78-WXXF-FW98
HistoryMay 01, 2022 - 7:45 a.m.

Cross-site scripting in Apache Tomcat

2022-05-0107:45:38
Google
osv.dev
18
apache tomcat
cross-site scripting
vulnerability
remote attackers
arbitrary web script
html
cve-2006-0254.

EPSS

0.958

Percentile

99.5%

Cross-site scripting (XSS) vulnerability in the calendar application example in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.31, 5.0.0 through 5.0.30, and 5.5.0 through 5.5.15 allows remote attackers to inject arbitrary web script or HTML via the time parameter to cal2.jsp and possibly unspecified other vectors. NOTE: this may be related to CVE-2006-0254.1.

References