Apache Tomcat is vulnerable to cross-site scripting (XSS). The vulnerabiilty is possible because there is no proper sanitization of input to the From
field in SendMailServlet (examples/jsp/mail/sendmail.jsp), allowing an attacker to inject arbitrary script through it.
lists.apple.com/archives/security-announce/2008//Jun/msg00002.html
osvdb.org/39000
seclists.org/fulldisclosure/2007/Jul/0448.html
secunia.com/advisories/30802
securityreason.com/securityalert/2918
support.apple.com/kb/HT2163
tomcat.apache.org/security-4.html
www.kb.cert.org/vuls/id/862600
www.securityfocus.com/archive/1/474413/100/0/threaded
www.securityfocus.com/bid/24999
www.vupen.com/english/advisories/2007/2618
www.vupen.com/english/advisories/2008/1981/references
exchange.xforce.ibmcloud.com/vulnerabilities/35536
lists.apache.org/thread.html/29dc6c2b625789e70a9c4756b5a327e6547273ff8bde7e0327af48c5@%3Cdev.tomcat.apache.org%3E
lists.apache.org/thread.html/c62b0e3a7bf23342352a5810c640a94b6db69957c5c19db507004d74@%3Cdev.tomcat.apache.org%3E
www.kb.cert.org/vuls/id/862600/