PT-2001-1997 · Apache · Apache Tomcat

Publicado

2001-11-22

·

Atualizado

2022-04-30

·

CVE-2001-0829

CVSS v2.0

5.1

Média

VetorAV:N/AC:H/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Apache Tomcat version 3.2.1
Description A cross-site scripting issue allows a malicious webmaster to embed Javascript in a request for a .JSP file, causing the Javascript to be inserted into an error message. The default 404 error page does not escape URLs, enabling XSS attacks using specially crafted URLs.
Recommendations For Apache Tomcat version 3.2.1, consider modifying the default 404 error page to properly escape URLs as a temporary workaround. Restrict access to .JSP files to minimize the risk of exploitation until a proper fix is applied. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2001-0829
GHSA-58HJ-575G-5J25

Produtos afetados

Apache Tomcat