PT-2007-5880 · Apache · Apache Tomcat

Tushar Vartak

·

Published

2007-09-05

·

Updated

2022-05-01

·

CVE-2007-4724

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions: Apache Tomcat version 4.1.31
Description: A cross-site request forgery issue exists in the calendar examples application, specifically in cal2.jsp. This allows remote attackers to add events as arbitrary users by manipulating the time and description parameters.
Recommendations: For Apache Tomcat version 4.1.31, as a temporary workaround, consider restricting access to the cal2.jsp page in the calendar examples application until a patch is available. Avoid using the time and description parameters in the affected page until the issue is resolved.

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-4724
GHSA-G77G-VJJM-X83J

Affected Products

Apache Tomcat