Lucene search

K
tomcatApache TomcatTOMCAT:9472937DC7D6CA449B23E8770CD44BA2
HistoryMar 08, 2007 - 12:00 a.m.

Fixed in Apache Tomcat 5.5.24, 5.0.SVN

2007-03-0800:00:00
Apache Tomcat
tomcat.apache.org
16

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

EPSS

0.103

Percentile

95.0%

Moderate: Cross-site scripting CVE-2007-1355

The JSP and Servlet included in the sample application within the Tomcat documentation webapp did not escape user provided data before including it in the output. This enabled a XSS attack. These pages have been simplified not to use any user provided data in the output.

Affects: 5.0.0-5.0.30, 5.5.0-5.5.23

Affected configurations

Vulners
Node
apachetomcatRange5.0.0
OR
apachetomcatRange5.0.30
OR
apachetomcatRange5.5.0
OR
apachetomcatRange5.5.23
VendorProductVersionCPE
apachetomcat*cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

EPSS

0.103

Percentile

95.0%