PT-2007-5880 · Apache · Apache Tomcat
Tushar Vartak
·
Publicado
2007-09-05
·
Atualizado
2022-05-01
·
CVE-2007-4724
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions:
Apache Tomcat version 4.1.31
Description:
A cross-site request forgery issue exists in the calendar examples application, specifically in cal2.jsp. This allows remote attackers to add events as arbitrary users by manipulating the
time and description parameters.Recommendations:
For Apache Tomcat version 4.1.31, as a temporary workaround, consider restricting access to the cal2.jsp page in the calendar examples application until a patch is available. Avoid using the
time and description parameters in the affected page until the issue is resolved.Correção
CSRF
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Apache Tomcat