PT-2001-1997 · Apache · Apache Tomcat
Publicado
2001-11-22
·
Atualizado
2022-04-30
·
CVE-2001-0829
CVSS v2.0
5.1
Média
| Vetor | AV:N/AC:H/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Apache Tomcat version 3.2.1
Description
A cross-site scripting issue allows a malicious webmaster to embed Javascript in a request for a .JSP file, causing the Javascript to be inserted into an error message. The default 404 error page does not escape URLs, enabling XSS attacks using specially crafted URLs.
Recommendations
For Apache Tomcat version 3.2.1, consider modifying the default 404 error page to properly escape URLs as a temporary workaround. Restrict access to .JSP files to minimize the risk of exploitation until a proper fix is applied. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Apache Tomcat