Логотип exploitDog
bind:"CVE-2008-2938" OR bind:"CVE-2008-1947" OR bind:"CVE-2008-2370" OR bind:"CVE-2008-1232"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2008-2938" OR bind:"CVE-2008-1947" OR bind:"CVE-2008-2370" OR bind:"CVE-2008-1232"

Количество 21

Количество 21

oracle-oval логотип

ELSA-2008-0648

почти 17 лет назад

ELSA-2008-0648: tomcat security update (IMPORTANT)

EPSS: Низкий
ubuntu логотип

CVE-2008-2938

почти 17 лет назад

Directory traversal vulnerability in Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16, when allowLinking and UTF-8 are enabled, allows remote attackers to read arbitrary files via encoded directory traversal sequences in the URI, a different vulnerability than CVE-2008-2370. NOTE: versions earlier than 6.0.18 were reported affected, but the vendor advisory lists 6.0.16 as the last affected version.

CVSS2: 4.3
EPSS: Критический
redhat логотип

CVE-2008-2938

почти 17 лет назад

Directory traversal vulnerability in Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16, when allowLinking and UTF-8 are enabled, allows remote attackers to read arbitrary files via encoded directory traversal sequences in the URI, a different vulnerability than CVE-2008-2370. NOTE: versions earlier than 6.0.18 were reported affected, but the vendor advisory lists 6.0.16 as the last affected version.

EPSS: Критический
nvd логотип

CVE-2008-2938

почти 17 лет назад

Directory traversal vulnerability in Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16, when allowLinking and UTF-8 are enabled, allows remote attackers to read arbitrary files via encoded directory traversal sequences in the URI, a different vulnerability than CVE-2008-2370. NOTE: versions earlier than 6.0.18 were reported affected, but the vendor advisory lists 6.0.16 as the last affected version.

CVSS2: 4.3
EPSS: Критический
debian логотип

CVE-2008-2938

почти 17 лет назад

Directory traversal vulnerability in Apache Tomcat 4.1.0 through 4.1.3 ...

CVSS2: 4.3
EPSS: Критический
github логотип

GHSA-m7xj-ccqc-p4g2

около 3 лет назад

Apache Tomcat Directory Traversal vulnerability

EPSS: Критический
ubuntu логотип

CVE-2008-1947

около 17 лет назад

Cross-site scripting (XSS) vulnerability in Apache Tomcat 5.5.9 through 5.5.26 and 6.0.0 through 6.0.16 allows remote attackers to inject arbitrary web script or HTML via the name parameter (aka the hostname attribute) to host-manager/html/add.

CVSS2: 4.3
EPSS: Средний
redhat логотип

CVE-2008-1947

около 17 лет назад

Cross-site scripting (XSS) vulnerability in Apache Tomcat 5.5.9 through 5.5.26 and 6.0.0 through 6.0.16 allows remote attackers to inject arbitrary web script or HTML via the name parameter (aka the hostname attribute) to host-manager/html/add.

EPSS: Средний
nvd логотип

CVE-2008-1947

около 17 лет назад

Cross-site scripting (XSS) vulnerability in Apache Tomcat 5.5.9 through 5.5.26 and 6.0.0 through 6.0.16 allows remote attackers to inject arbitrary web script or HTML via the name parameter (aka the hostname attribute) to host-manager/html/add.

CVSS2: 4.3
EPSS: Средний
debian логотип

CVE-2008-1947

около 17 лет назад

Cross-site scripting (XSS) vulnerability in Apache Tomcat 5.5.9 throug ...

CVSS2: 4.3
EPSS: Средний
github логотип

GHSA-f98p-9pp6-7q6c

около 3 лет назад

Apache Tomcat Cross-site scripting (XSS) vulnerability

EPSS: Средний
ubuntu логотип

CVE-2008-2370

почти 17 лет назад

Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16, when a RequestDispatcher is used, performs path normalization before removing the query string from the URI, which allows remote attackers to conduct directory traversal attacks and read arbitrary files via a .. (dot dot) in a request parameter.

CVSS2: 5
EPSS: Высокий
redhat логотип

CVE-2008-2370

почти 17 лет назад

Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16, when a RequestDispatcher is used, performs path normalization before removing the query string from the URI, which allows remote attackers to conduct directory traversal attacks and read arbitrary files via a .. (dot dot) in a request parameter.

EPSS: Высокий
nvd логотип

CVE-2008-2370

почти 17 лет назад

Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16, when a RequestDispatcher is used, performs path normalization before removing the query string from the URI, which allows remote attackers to conduct directory traversal attacks and read arbitrary files via a .. (dot dot) in a request parameter.

CVSS2: 5
EPSS: Высокий
debian логотип

CVE-2008-2370

почти 17 лет назад

Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 th ...

CVSS2: 5
EPSS: Высокий
ubuntu логотип

CVE-2008-1232

почти 17 лет назад

Cross-site scripting (XSS) vulnerability in Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16 allows remote attackers to inject arbitrary web script or HTML via a crafted string that is used in the message argument to the HttpServletResponse.sendError method.

CVSS2: 4.3
EPSS: Средний
redhat логотип

CVE-2008-1232

почти 17 лет назад

Cross-site scripting (XSS) vulnerability in Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16 allows remote attackers to inject arbitrary web script or HTML via a crafted string that is used in the message argument to the HttpServletResponse.sendError method.

EPSS: Средний
nvd логотип

CVE-2008-1232

почти 17 лет назад

Cross-site scripting (XSS) vulnerability in Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16 allows remote attackers to inject arbitrary web script or HTML via a crafted string that is used in the message argument to the HttpServletResponse.sendError method.

CVSS2: 4.3
EPSS: Средний
debian логотип

CVE-2008-1232

почти 17 лет назад

Cross-site scripting (XSS) vulnerability in Apache Tomcat 4.1.0 throug ...

CVSS2: 4.3
EPSS: Средний
github логотип

GHSA-q74x-qqhr-f8rx

около 3 лет назад

Apache Tomcat Cross-site scripting (XSS) vulnerability

EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
oracle-oval логотип
ELSA-2008-0648

ELSA-2008-0648: tomcat security update (IMPORTANT)

почти 17 лет назад
ubuntu логотип
CVE-2008-2938

Directory traversal vulnerability in Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16, when allowLinking and UTF-8 are enabled, allows remote attackers to read arbitrary files via encoded directory traversal sequences in the URI, a different vulnerability than CVE-2008-2370. NOTE: versions earlier than 6.0.18 were reported affected, but the vendor advisory lists 6.0.16 as the last affected version.

CVSS2: 4.3
93%
Критический
почти 17 лет назад
redhat логотип
CVE-2008-2938

Directory traversal vulnerability in Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16, when allowLinking and UTF-8 are enabled, allows remote attackers to read arbitrary files via encoded directory traversal sequences in the URI, a different vulnerability than CVE-2008-2370. NOTE: versions earlier than 6.0.18 were reported affected, but the vendor advisory lists 6.0.16 as the last affected version.

93%
Критический
почти 17 лет назад
nvd логотип
CVE-2008-2938

Directory traversal vulnerability in Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16, when allowLinking and UTF-8 are enabled, allows remote attackers to read arbitrary files via encoded directory traversal sequences in the URI, a different vulnerability than CVE-2008-2370. NOTE: versions earlier than 6.0.18 were reported affected, but the vendor advisory lists 6.0.16 as the last affected version.

CVSS2: 4.3
93%
Критический
почти 17 лет назад
debian логотип
CVE-2008-2938

Directory traversal vulnerability in Apache Tomcat 4.1.0 through 4.1.3 ...

CVSS2: 4.3
93%
Критический
почти 17 лет назад
github логотип
GHSA-m7xj-ccqc-p4g2

Apache Tomcat Directory Traversal vulnerability

93%
Критический
около 3 лет назад
ubuntu логотип
CVE-2008-1947

Cross-site scripting (XSS) vulnerability in Apache Tomcat 5.5.9 through 5.5.26 and 6.0.0 through 6.0.16 allows remote attackers to inject arbitrary web script or HTML via the name parameter (aka the hostname attribute) to host-manager/html/add.

CVSS2: 4.3
49%
Средний
около 17 лет назад
redhat логотип
CVE-2008-1947

Cross-site scripting (XSS) vulnerability in Apache Tomcat 5.5.9 through 5.5.26 and 6.0.0 through 6.0.16 allows remote attackers to inject arbitrary web script or HTML via the name parameter (aka the hostname attribute) to host-manager/html/add.

49%
Средний
около 17 лет назад
nvd логотип
CVE-2008-1947

Cross-site scripting (XSS) vulnerability in Apache Tomcat 5.5.9 through 5.5.26 and 6.0.0 through 6.0.16 allows remote attackers to inject arbitrary web script or HTML via the name parameter (aka the hostname attribute) to host-manager/html/add.

CVSS2: 4.3
49%
Средний
около 17 лет назад
debian логотип
CVE-2008-1947

Cross-site scripting (XSS) vulnerability in Apache Tomcat 5.5.9 throug ...

CVSS2: 4.3
49%
Средний
около 17 лет назад
github логотип
GHSA-f98p-9pp6-7q6c

Apache Tomcat Cross-site scripting (XSS) vulnerability

49%
Средний
около 3 лет назад
ubuntu логотип
CVE-2008-2370

Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16, when a RequestDispatcher is used, performs path normalization before removing the query string from the URI, which allows remote attackers to conduct directory traversal attacks and read arbitrary files via a .. (dot dot) in a request parameter.

CVSS2: 5
89%
Высокий
почти 17 лет назад
redhat логотип
CVE-2008-2370

Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16, when a RequestDispatcher is used, performs path normalization before removing the query string from the URI, which allows remote attackers to conduct directory traversal attacks and read arbitrary files via a .. (dot dot) in a request parameter.

89%
Высокий
почти 17 лет назад
nvd логотип
CVE-2008-2370

Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16, when a RequestDispatcher is used, performs path normalization before removing the query string from the URI, which allows remote attackers to conduct directory traversal attacks and read arbitrary files via a .. (dot dot) in a request parameter.

CVSS2: 5
89%
Высокий
почти 17 лет назад
debian логотип
CVE-2008-2370

Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 th ...

CVSS2: 5
89%
Высокий
почти 17 лет назад
ubuntu логотип
CVE-2008-1232

Cross-site scripting (XSS) vulnerability in Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16 allows remote attackers to inject arbitrary web script or HTML via a crafted string that is used in the message argument to the HttpServletResponse.sendError method.

CVSS2: 4.3
38%
Средний
почти 17 лет назад
redhat логотип
CVE-2008-1232

Cross-site scripting (XSS) vulnerability in Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16 allows remote attackers to inject arbitrary web script or HTML via a crafted string that is used in the message argument to the HttpServletResponse.sendError method.

38%
Средний
почти 17 лет назад
nvd логотип
CVE-2008-1232

Cross-site scripting (XSS) vulnerability in Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16 allows remote attackers to inject arbitrary web script or HTML via a crafted string that is used in the message argument to the HttpServletResponse.sendError method.

CVSS2: 4.3
38%
Средний
почти 17 лет назад
debian логотип
CVE-2008-1232

Cross-site scripting (XSS) vulnerability in Apache Tomcat 4.1.0 throug ...

CVSS2: 4.3
38%
Средний
почти 17 лет назад
github логотип
GHSA-q74x-qqhr-f8rx

Apache Tomcat Cross-site scripting (XSS) vulnerability

38%
Средний
около 3 лет назад

Уязвимостей на страницу