Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2010-4172

Опубликовано: 22 нояб. 2010
Источник: redhat
CVSS2: 4.3
EPSS Средний

Описание

Multiple cross-site scripting (XSS) vulnerabilities in the Manager application in Apache Tomcat 6.0.12 through 6.0.29 and 7.0.0 through 7.0.4 allow remote attackers to inject arbitrary web script or HTML via the (1) orderBy or (2) sort parameter to sessionsList.jsp, or unspecified input to (3) sessionDetail.jsp or (4) java/org/apache/catalina/manager/JspHelper.java, related to use of untrusted web applications.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5tomcat5Not affected
Red Hat Enterprise Linux 6tomcat6FixedRHSA-2011:079119.05.2011
Red Hat JBoss Enterprise Web Server 1 for RHEL 5antFixedRHSA-2011:089722.06.2011
Red Hat JBoss Enterprise Web Server 1 for RHEL 5antlrFixedRHSA-2011:089722.06.2011
Red Hat JBoss Enterprise Web Server 1 for RHEL 5cglibFixedRHSA-2011:089722.06.2011
Red Hat JBoss Enterprise Web Server 1 for RHEL 5dom4jFixedRHSA-2011:089722.06.2011
Red Hat JBoss Enterprise Web Server 1 for RHEL 5ecj3FixedRHSA-2011:089722.06.2011
Red Hat JBoss Enterprise Web Server 1 for RHEL 5glassfish-jsfFixedRHSA-2011:089722.06.2011
Red Hat JBoss Enterprise Web Server 1 for RHEL 5hibernate3FixedRHSA-2011:089722.06.2011
Red Hat JBoss Enterprise Web Server 1 for RHEL 5hibernate3-annotationsFixedRHSA-2011:089722.06.2011

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=656246tomcat: cross-site-scripting vulnerability in the manager application

EPSS

Процентиль: 99%
0.42009
Средний

4.3 Medium

CVSS2

Связанные уязвимости

ubuntu
почти 16 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the Manager application in Apache Tomcat 6.0.12 through 6.0.29 and 7.0.0 through 7.0.4 allow remote attackers to inject arbitrary web script or HTML via the (1) orderBy or (2) sort parameter to sessionsList.jsp, or unspecified input to (3) sessionDetail.jsp or (4) java/org/apache/catalina/manager/JspHelper.java, related to use of untrusted web applications.

nvd
почти 16 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the Manager application in Apache Tomcat 6.0.12 through 6.0.29 and 7.0.0 through 7.0.4 allow remote attackers to inject arbitrary web script or HTML via the (1) orderBy or (2) sort parameter to sessionsList.jsp, or unspecified input to (3) sessionDetail.jsp or (4) java/org/apache/catalina/manager/JspHelper.java, related to use of untrusted web applications.

debian
почти 16 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the Manager app ...

github
больше 4 лет назад

Improper Neutralization of Input During Web Page Generation in Apache Tomcat

oracle-oval
больше 15 лет назад

ELSA-2011-0791: tomcat6 security and bug fix update (MODERATE)

EPSS

Процентиль: 99%
0.42009
Средний

4.3 Medium

CVSS2