PT-2007-5880 · Apache · Apache Tomcat
Tushar Vartak
·
Published
2007-09-05
·
Updated
2022-05-01
·
CVE-2007-4724
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions:
Apache Tomcat version 4.1.31
Description:
A cross-site request forgery issue exists in the calendar examples application, specifically in cal2.jsp. This allows remote attackers to add events as arbitrary users by manipulating the
time and description parameters.Recommendations:
For Apache Tomcat version 4.1.31, as a temporary workaround, consider restricting access to the cal2.jsp page in the calendar examples application until a patch is available. Avoid using the
time and description parameters in the affected page until the issue is resolved.Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Tomcat