PT-2006-7519 · Apache+2 · Apache Tomcat+2

Published

2006-12-18

·

Updated

2022-05-01

·

CVE-2007-1358

CVSS v2.0

2.6

Low

VectorAV:N/AC:H/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions: Apache Tomcat versions 4.0.0 through 4.0.6 Apache Tomcat versions 4.1.0 through 4.1.34
Description: The issue allows remote attackers to inject arbitrary web script or HTML via crafted Accept-Language headers that do not conform to RFC 2616, potentially leading to cross-site scripting (XSS) attacks.
Recommendations: For Apache Tomcat versions 4.0.0 through 4.0.6, update to a version outside of this range to mitigate the risk. For Apache Tomcat versions 4.1.0 through 4.1.34, update to a version outside of this range to mitigate the risk. As a temporary workaround, consider restricting access to the Accept-Language header to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-1358
GHSA-XMC9-6P56-3C4V
HPSBUX02262
RHSA-2007:0326
RHSA-2007:0327
RHSA-2007:0328
RHSA-2007:0360
RHSA-2007:0876
RHSA-2007_0327
RHSA-2008:0261
RHSA-2008:0524
RHSA-2008:0630
RHSA-2010:0602

Affected Products

Apache Tomcat
Hp-Ux
Red Hat