PT-2007-5880 · Apache · Apache Tomcat

Tushar Vartak

·

Publicado

2007-09-05

·

Atualizado

2022-05-01

·

CVE-2007-4724

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions: Apache Tomcat version 4.1.31
Description: A cross-site request forgery issue exists in the calendar examples application, specifically in cal2.jsp. This allows remote attackers to add events as arbitrary users by manipulating the time and description parameters.
Recommendations: For Apache Tomcat version 4.1.31, as a temporary workaround, consider restricting access to the cal2.jsp page in the calendar examples application until a patch is available. Avoid using the time and description parameters in the affected page until the issue is resolved.

Correção

CSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2007-4724
GHSA-G77G-VJJM-X83J

Produtos afetados

Apache Tomcat