Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Tomcat

Tomcatконтейнер сервлетов с открытым исходным кодом

Релизный цикл, информация об уязвимостях

Продукт: Tomcat
Вендор: apache

График релизов

9.010.010.111.0201720182019202020212022202320242025202620272028

Недавние уязвимости Tomcat

Количество 1 531

redhat логотип

CVE-2007-3382

около 19 лет назад

Apache Tomcat 6.0.0 to 6.0.13, 5.5.0 to 5.5.24, 5.0.0 to 5.0.30, 4.1.0 to 4.1.36, and 3.3 to 3.3.2 treats single quotes ("'") as delimiters in cookies, which might cause sensitive information such as session IDs to be leaked and allow remote attackers to conduct session hijacking attacks.

EPSS: Средний
redhat логотип

CVE-2007-3386

около 19 лет назад

Cross-site scripting (XSS) vulnerability in the Host Manager Servlet for Apache Tomcat 6.0.0 to 6.0.13 and 5.5.0 to 5.5.24 allows remote attackers to inject arbitrary HTML and web script via crafted requests, as demonstrated using the aliases parameter to an html/add action.

EPSS: Средний
nvd логотип

CVE-2007-3384

около 19 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in examples/servlet/CookieExample in Apache Tomcat 3.3 through 3.3.2 allow remote attackers to inject arbitrary web script or HTML via the (1) Name or (2) Value field, related to error messages.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2007-3383

около 19 лет назад

Cross-site scripting (XSS) vulnerability in SendMailServlet in the examples web application (examples/jsp/mail/sendmail.jsp) in Apache Tomcat 4.0.0 through 4.0.6 and 4.1.0 through 4.1.36 allows remote attackers to inject arbitrary web script or HTML via the From field and possibly other fields, related to generation of error messages.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2007-3383

около 19 лет назад

Cross-site scripting (XSS) vulnerability in SendMailServlet in the exa ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2007-3383

около 19 лет назад

Cross-site scripting (XSS) vulnerability in SendMailServlet in the examples web application (examples/jsp/mail/sendmail.jsp) in Apache Tomcat 4.0.0 through 4.0.6 and 4.1.0 through 4.1.36 allows remote attackers to inject arbitrary web script or HTML via the From field and possibly other fields, related to generation of error messages.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2007-2449

больше 19 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in certain JSP files in the examples web application in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.36, 5.0.0 through 5.0.30, 5.5.0 through 5.5.24, and 6.0.0 through 6.0.13 allow remote attackers to inject arbitrary web script or HTML via the portion of the URI after the ';' character, as demonstrated by a URI containing a "snp/snoop.jsp;" sequence.

CVSS2: 4.3
EPSS: Высокий
nvd логотип

CVE-2007-2450

больше 19 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the (1) Manager and (2) Host Manager web applications in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.36, 5.0.0 through 5.0.30, 5.5.0 through 5.5.24, and 6.0.0 through 6.0.13 allow remote authenticated users to inject arbitrary web script or HTML via a parameter name to manager/html/upload, and other unspecified vectors.

CVSS2: 3.5
EPSS: Низкий
debian логотип

CVE-2007-2449

больше 19 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in certain JSP fil ...

CVSS2: 4.3
EPSS: Высокий
debian логотип

CVE-2007-2450

больше 19 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the (1) Manager ...

CVSS2: 3.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
redhat логотип
CVE-2007-3382

Apache Tomcat 6.0.0 to 6.0.13, 5.5.0 to 5.5.24, 5.0.0 to 5.0.30, 4.1.0 to 4.1.36, and 3.3 to 3.3.2 treats single quotes ("'") as delimiters in cookies, which might cause sensitive information such as session IDs to be leaked and allow remote attackers to conduct session hijacking attacks.

37%
Средний
около 19 лет назад
redhat логотип
CVE-2007-3386

Cross-site scripting (XSS) vulnerability in the Host Manager Servlet for Apache Tomcat 6.0.0 to 6.0.13 and 5.5.0 to 5.5.24 allows remote attackers to inject arbitrary HTML and web script via crafted requests, as demonstrated using the aliases parameter to an html/add action.

59%
Средний
около 19 лет назад
nvd логотип
CVE-2007-3384

Multiple cross-site scripting (XSS) vulnerabilities in examples/servlet/CookieExample in Apache Tomcat 3.3 through 3.3.2 allow remote attackers to inject arbitrary web script or HTML via the (1) Name or (2) Value field, related to error messages.

CVSS2: 4.3
3%
Низкий
около 19 лет назад
nvd логотип
CVE-2007-3383

Cross-site scripting (XSS) vulnerability in SendMailServlet in the examples web application (examples/jsp/mail/sendmail.jsp) in Apache Tomcat 4.0.0 through 4.0.6 and 4.1.0 through 4.1.36 allows remote attackers to inject arbitrary web script or HTML via the From field and possibly other fields, related to generation of error messages.

CVSS2: 4.3
9%
Низкий
около 19 лет назад
debian логотип
CVE-2007-3383

Cross-site scripting (XSS) vulnerability in SendMailServlet in the exa ...

CVSS2: 4.3
9%
Низкий
около 19 лет назад
ubuntu логотип
CVE-2007-3383

Cross-site scripting (XSS) vulnerability in SendMailServlet in the examples web application (examples/jsp/mail/sendmail.jsp) in Apache Tomcat 4.0.0 through 4.0.6 and 4.1.0 through 4.1.36 allows remote attackers to inject arbitrary web script or HTML via the From field and possibly other fields, related to generation of error messages.

CVSS2: 4.3
9%
Низкий
около 19 лет назад
nvd логотип
CVE-2007-2449

Multiple cross-site scripting (XSS) vulnerabilities in certain JSP files in the examples web application in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.36, 5.0.0 through 5.0.30, 5.5.0 through 5.5.24, and 6.0.0 through 6.0.13 allow remote attackers to inject arbitrary web script or HTML via the portion of the URI after the ';' character, as demonstrated by a URI containing a "snp/snoop.jsp;" sequence.

CVSS2: 4.3
77%
Высокий
больше 19 лет назад
nvd логотип
CVE-2007-2450

Multiple cross-site scripting (XSS) vulnerabilities in the (1) Manager and (2) Host Manager web applications in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.36, 5.0.0 through 5.0.30, 5.5.0 through 5.5.24, and 6.0.0 through 6.0.13 allow remote authenticated users to inject arbitrary web script or HTML via a parameter name to manager/html/upload, and other unspecified vectors.

CVSS2: 3.5
3%
Низкий
больше 19 лет назад
debian логотип
CVE-2007-2449

Multiple cross-site scripting (XSS) vulnerabilities in certain JSP fil ...

CVSS2: 4.3
77%
Высокий
больше 19 лет назад
debian логотип
CVE-2007-2450

Multiple cross-site scripting (XSS) vulnerabilities in the (1) Manager ...

CVSS2: 3.5
3%
Низкий
больше 19 лет назад

Уязвимостей на страницу


Поделиться