PT-2003-1329 · Apache · Jakarta Tomcat+1
Publicado
2003-01-29
·
Atualizado
2022-04-29
·
CVE-2003-0044
CVSS v2.0
6.8
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Jakarta Tomcat versions 3.x through 3.3.1a
Description
The issue concerns multiple cross-site scripting (XSS) vulnerabilities found in the examples and ROOT web applications. These vulnerabilities allow remote attackers to insert arbitrary web script or HTML. It is noted that the examples web application should not be installed on production servers due to these vulnerabilities.
Recommendations
For Jakarta Tomcat versions 3.x through 3.3.1a, consider uninstalling the examples web application to minimize the risk of exploitation, especially on production servers. As a temporary workaround, restrict access to the ROOT web application and the examples web application until a fix is available.
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Apache Tomcat
Jakarta Tomcat