Lucene search

K
ubuntucveUbuntu.comUB:CVE-2009-0781
HistoryMar 09, 2009 - 12:00 a.m.

CVE-2009-0781

2009-03-0900:00:00
ubuntu.com
ubuntu.com
19

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

0.162 Low

EPSS

Percentile

96.0%

Cross-site scripting (XSS) vulnerability in jsp/cal/cal2.jsp in the
calendar application in the examples web application in Apache Tomcat 4.1.0
through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18 allows
remote attackers to inject arbitrary web script or HTML via the time
parameter, related to “invalid HTML.”

Bugs

Notes

Author Note
mdeslaur PoC: http://seclists.org/bugtraq/2009/Mar/0054.html
OSVersionArchitecturePackageVersionFilename
ubuntu8.10noarchtomcat6< 6.0.18-0ubuntu3.2UNKNOWN
ubuntu9.04noarchtomcat6< 6.0.18-0ubuntu6.1UNKNOWN

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

0.162 Low

EPSS

Percentile

96.0%