PT-2007-1472 · Apache+1 · Apache Tomcat+1
Published
2007-05-09
·
Updated
2023-02-13
·
CVE-2006-7195
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Apache Tomcat versions 5.0.0 through 5.0.30
Apache Tomcat versions 5.5.0 through 5.5.17
Description
A cross-site scripting (XSS) issue exists due to unfiltered header values in the implicit-objects.jsp file of the examples webapp, allowing remote attackers to inject arbitrary web script or HTML. This enables a XSS attack.
Recommendations
For Apache Tomcat versions 5.0.0 through 5.0.30, filter the header values in the implicit-objects.jsp file to prevent XSS attacks.
For Apache Tomcat versions 5.5.0 through 5.5.17, filter the header values in the implicit-objects.jsp file to prevent XSS attacks.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apache Tomcat
Red Hat