Описание
Cross-site scripting (XSS) vulnerability in jsp/cal/cal2.jsp in the calendar application in the examples web application in Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18 allows remote attackers to inject arbitrary web script or HTML via the time parameter, related to "invalid HTML."
Релиз | Статус | Примечание |
---|---|---|
dapper | DNE | |
devel | DNE | |
gutsy | ignored | end of life, was needed |
hardy | ignored | end of life |
intrepid | ignored | end of life, was needed |
jaunty | ignored | end of life |
karmic | DNE | |
lucid | DNE | |
maverick | DNE | |
natty | DNE |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
dapper | DNE | |
devel | not-affected | 6.0.20-1ubuntu1 |
gutsy | DNE | |
hardy | DNE | |
intrepid | released | 6.0.18-0ubuntu3.2 |
jaunty | released | 6.0.18-0ubuntu6.1 |
karmic | not-affected | 6.0.20-1ubuntu1 |
lucid | not-affected | 6.0.20-1ubuntu1 |
maverick | not-affected | 6.0.20-1ubuntu1 |
natty | not-affected | 6.0.20-1ubuntu1 |
Показывать по
EPSS
4.3 Medium
CVSS2
Связанные уязвимости
Cross-site scripting (XSS) vulnerability in jsp/cal/cal2.jsp in the calendar application in the examples web application in Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18 allows remote attackers to inject arbitrary web script or HTML via the time parameter, related to "invalid HTML."
Cross-site scripting (XSS) vulnerability in jsp/cal/cal2.jsp in the calendar application in the examples web application in Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18 allows remote attackers to inject arbitrary web script or HTML via the time parameter, related to "invalid HTML."
Cross-site scripting (XSS) vulnerability in jsp/cal/cal2.jsp in the ca ...
EPSS
4.3 Medium
CVSS2