Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c78g-qwpw-2jgv

Опубликовано: 14 мая 2022
Источник: github
Github: Прошло ревью

Описание

Improper Neutralization of Input During Web Page Generation in Apache Tomcat

Multiple cross-site scripting (XSS) vulnerabilities in the Manager application in Apache Tomcat 6.0.12 through 6.0.29 and 7.0.0 through 7.0.4 allow remote attackers to inject arbitrary web script or HTML via the (1) orderBy or (2) sort parameter to sessionsList.jsp, or unspecified input to (3) sessionDetail.jsp or (4) java/org/apache/catalina/manager/JspHelper.java, related to use of untrusted web applications.

Пакеты

Наименование

org.apache.tomcat:tomcat

maven
Затронутые версииВерсия исправления

>= 7.0.0, < 7.0.5

7.0.5

Наименование

org.apache.tomcat:tomcat

maven
Затронутые версииВерсия исправления

>= 6.0.12, <= 6.0.29

Отсутствует

EPSS

Процентиль: 96%
0.22781
Средний

Дефекты

CWE-79

Связанные уязвимости

ubuntu
больше 14 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the Manager application in Apache Tomcat 6.0.12 through 6.0.29 and 7.0.0 through 7.0.4 allow remote attackers to inject arbitrary web script or HTML via the (1) orderBy or (2) sort parameter to sessionsList.jsp, or unspecified input to (3) sessionDetail.jsp or (4) java/org/apache/catalina/manager/JspHelper.java, related to use of untrusted web applications.

redhat
больше 14 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the Manager application in Apache Tomcat 6.0.12 through 6.0.29 and 7.0.0 through 7.0.4 allow remote attackers to inject arbitrary web script or HTML via the (1) orderBy or (2) sort parameter to sessionsList.jsp, or unspecified input to (3) sessionDetail.jsp or (4) java/org/apache/catalina/manager/JspHelper.java, related to use of untrusted web applications.

nvd
больше 14 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the Manager application in Apache Tomcat 6.0.12 through 6.0.29 and 7.0.0 through 7.0.4 allow remote attackers to inject arbitrary web script or HTML via the (1) orderBy or (2) sort parameter to sessionsList.jsp, or unspecified input to (3) sessionDetail.jsp or (4) java/org/apache/catalina/manager/JspHelper.java, related to use of untrusted web applications.

debian
больше 14 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the Manager app ...

oracle-oval
около 14 лет назад

ELSA-2011-0791: tomcat6 security and bug fix update (MODERATE)

EPSS

Процентиль: 96%
0.22781
Средний

Дефекты

CWE-79