Логотип exploitDog
bind:"CVE-2011-0013" OR bind:"CVE-2010-4172" OR bind:"CVE-2010-3718"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2011-0013" OR bind:"CVE-2010-4172" OR bind:"CVE-2010-3718"

Количество 17

Количество 17

oracle-oval логотип

ELSA-2011-0791

около 14 лет назад

ELSA-2011-0791: tomcat6 security and bug fix update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2011-1845

больше 13 лет назад

ELSA-2011-1845: tomcat5 security update (MODERATE)

EPSS: Низкий
ubuntu логотип

CVE-2011-0013

больше 14 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the HTML Manager Interface in Apache Tomcat 5.5 before 5.5.32, 6.0 before 6.0.30, and 7.0 before 7.0.6 allow remote attackers to inject arbitrary web script or HTML, as demonstrated via the display-name tag.

CVSS2: 4.3
EPSS: Средний
redhat логотип

CVE-2011-0013

больше 14 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the HTML Manager Interface in Apache Tomcat 5.5 before 5.5.32, 6.0 before 6.0.30, and 7.0 before 7.0.6 allow remote attackers to inject arbitrary web script or HTML, as demonstrated via the display-name tag.

CVSS2: 4.3
EPSS: Средний
nvd логотип

CVE-2011-0013

больше 14 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the HTML Manager Interface in Apache Tomcat 5.5 before 5.5.32, 6.0 before 6.0.30, and 7.0 before 7.0.6 allow remote attackers to inject arbitrary web script or HTML, as demonstrated via the display-name tag.

CVSS2: 4.3
EPSS: Средний
debian логотип

CVE-2011-0013

больше 14 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the HTML Manage ...

CVSS2: 4.3
EPSS: Средний
github логотип

GHSA-3p86-xgrq-m6p6

около 3 лет назад

Improper Neutralization of Input During Web Page Generation in Apache Tomcat

EPSS: Средний
ubuntu логотип

CVE-2010-4172

больше 14 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the Manager application in Apache Tomcat 6.0.12 through 6.0.29 and 7.0.0 through 7.0.4 allow remote attackers to inject arbitrary web script or HTML via the (1) orderBy or (2) sort parameter to sessionsList.jsp, or unspecified input to (3) sessionDetail.jsp or (4) java/org/apache/catalina/manager/JspHelper.java, related to use of untrusted web applications.

CVSS2: 4.3
EPSS: Средний
redhat логотип

CVE-2010-4172

больше 14 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the Manager application in Apache Tomcat 6.0.12 through 6.0.29 and 7.0.0 through 7.0.4 allow remote attackers to inject arbitrary web script or HTML via the (1) orderBy or (2) sort parameter to sessionsList.jsp, or unspecified input to (3) sessionDetail.jsp or (4) java/org/apache/catalina/manager/JspHelper.java, related to use of untrusted web applications.

CVSS2: 4.3
EPSS: Средний
nvd логотип

CVE-2010-4172

больше 14 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the Manager application in Apache Tomcat 6.0.12 through 6.0.29 and 7.0.0 through 7.0.4 allow remote attackers to inject arbitrary web script or HTML via the (1) orderBy or (2) sort parameter to sessionsList.jsp, or unspecified input to (3) sessionDetail.jsp or (4) java/org/apache/catalina/manager/JspHelper.java, related to use of untrusted web applications.

CVSS2: 4.3
EPSS: Средний
debian логотип

CVE-2010-4172

больше 14 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the Manager app ...

CVSS2: 4.3
EPSS: Средний
ubuntu логотип

CVE-2010-3718

больше 14 лет назад

Apache Tomcat 7.0.0 through 7.0.3, 6.0.x, and 5.5.x, when running within a SecurityManager, does not make the ServletContext attribute read-only, which allows local web applications to read or write files outside of the intended working directory, as demonstrated using a directory traversal attack.

CVSS2: 1.2
EPSS: Низкий
redhat логотип

CVE-2010-3718

больше 14 лет назад

Apache Tomcat 7.0.0 through 7.0.3, 6.0.x, and 5.5.x, when running within a SecurityManager, does not make the ServletContext attribute read-only, which allows local web applications to read or write files outside of the intended working directory, as demonstrated using a directory traversal attack.

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2010-3718

больше 14 лет назад

Apache Tomcat 7.0.0 through 7.0.3, 6.0.x, and 5.5.x, when running within a SecurityManager, does not make the ServletContext attribute read-only, which allows local web applications to read or write files outside of the intended working directory, as demonstrated using a directory traversal attack.

CVSS2: 1.2
EPSS: Низкий
debian логотип

CVE-2010-3718

больше 14 лет назад

Apache Tomcat 7.0.0 through 7.0.3, 6.0.x, and 5.5.x, when running with ...

CVSS2: 1.2
EPSS: Низкий
github логотип

GHSA-c78g-qwpw-2jgv

около 3 лет назад

Improper Neutralization of Input During Web Page Generation in Apache Tomcat

EPSS: Средний
github логотип

GHSA-fj6c-prgj-gr3r

около 3 лет назад

Improper Limitation of a Pathname to a Restricted Directory in Apache Tomcat

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
oracle-oval логотип
ELSA-2011-0791

ELSA-2011-0791: tomcat6 security and bug fix update (MODERATE)

около 14 лет назад
oracle-oval логотип
ELSA-2011-1845

ELSA-2011-1845: tomcat5 security update (MODERATE)

больше 13 лет назад
ubuntu логотип
CVE-2011-0013

Multiple cross-site scripting (XSS) vulnerabilities in the HTML Manager Interface in Apache Tomcat 5.5 before 5.5.32, 6.0 before 6.0.30, and 7.0 before 7.0.6 allow remote attackers to inject arbitrary web script or HTML, as demonstrated via the display-name tag.

CVSS2: 4.3
32%
Средний
больше 14 лет назад
redhat логотип
CVE-2011-0013

Multiple cross-site scripting (XSS) vulnerabilities in the HTML Manager Interface in Apache Tomcat 5.5 before 5.5.32, 6.0 before 6.0.30, and 7.0 before 7.0.6 allow remote attackers to inject arbitrary web script or HTML, as demonstrated via the display-name tag.

CVSS2: 4.3
32%
Средний
больше 14 лет назад
nvd логотип
CVE-2011-0013

Multiple cross-site scripting (XSS) vulnerabilities in the HTML Manager Interface in Apache Tomcat 5.5 before 5.5.32, 6.0 before 6.0.30, and 7.0 before 7.0.6 allow remote attackers to inject arbitrary web script or HTML, as demonstrated via the display-name tag.

CVSS2: 4.3
32%
Средний
больше 14 лет назад
debian логотип
CVE-2011-0013

Multiple cross-site scripting (XSS) vulnerabilities in the HTML Manage ...

CVSS2: 4.3
32%
Средний
больше 14 лет назад
github логотип
GHSA-3p86-xgrq-m6p6

Improper Neutralization of Input During Web Page Generation in Apache Tomcat

32%
Средний
около 3 лет назад
ubuntu логотип
CVE-2010-4172

Multiple cross-site scripting (XSS) vulnerabilities in the Manager application in Apache Tomcat 6.0.12 through 6.0.29 and 7.0.0 through 7.0.4 allow remote attackers to inject arbitrary web script or HTML via the (1) orderBy or (2) sort parameter to sessionsList.jsp, or unspecified input to (3) sessionDetail.jsp or (4) java/org/apache/catalina/manager/JspHelper.java, related to use of untrusted web applications.

CVSS2: 4.3
23%
Средний
больше 14 лет назад
redhat логотип
CVE-2010-4172

Multiple cross-site scripting (XSS) vulnerabilities in the Manager application in Apache Tomcat 6.0.12 through 6.0.29 and 7.0.0 through 7.0.4 allow remote attackers to inject arbitrary web script or HTML via the (1) orderBy or (2) sort parameter to sessionsList.jsp, or unspecified input to (3) sessionDetail.jsp or (4) java/org/apache/catalina/manager/JspHelper.java, related to use of untrusted web applications.

CVSS2: 4.3
23%
Средний
больше 14 лет назад
nvd логотип
CVE-2010-4172

Multiple cross-site scripting (XSS) vulnerabilities in the Manager application in Apache Tomcat 6.0.12 through 6.0.29 and 7.0.0 through 7.0.4 allow remote attackers to inject arbitrary web script or HTML via the (1) orderBy or (2) sort parameter to sessionsList.jsp, or unspecified input to (3) sessionDetail.jsp or (4) java/org/apache/catalina/manager/JspHelper.java, related to use of untrusted web applications.

CVSS2: 4.3
23%
Средний
больше 14 лет назад
debian логотип
CVE-2010-4172

Multiple cross-site scripting (XSS) vulnerabilities in the Manager app ...

CVSS2: 4.3
23%
Средний
больше 14 лет назад
ubuntu логотип
CVE-2010-3718

Apache Tomcat 7.0.0 through 7.0.3, 6.0.x, and 5.5.x, when running within a SecurityManager, does not make the ServletContext attribute read-only, which allows local web applications to read or write files outside of the intended working directory, as demonstrated using a directory traversal attack.

CVSS2: 1.2
0%
Низкий
больше 14 лет назад
redhat логотип
CVE-2010-3718

Apache Tomcat 7.0.0 through 7.0.3, 6.0.x, and 5.5.x, when running within a SecurityManager, does not make the ServletContext attribute read-only, which allows local web applications to read or write files outside of the intended working directory, as demonstrated using a directory traversal attack.

CVSS2: 4
0%
Низкий
больше 14 лет назад
nvd логотип
CVE-2010-3718

Apache Tomcat 7.0.0 through 7.0.3, 6.0.x, and 5.5.x, when running within a SecurityManager, does not make the ServletContext attribute read-only, which allows local web applications to read or write files outside of the intended working directory, as demonstrated using a directory traversal attack.

CVSS2: 1.2
0%
Низкий
больше 14 лет назад
debian логотип
CVE-2010-3718

Apache Tomcat 7.0.0 through 7.0.3, 6.0.x, and 5.5.x, when running with ...

CVSS2: 1.2
0%
Низкий
больше 14 лет назад
github логотип
GHSA-c78g-qwpw-2jgv

Improper Neutralization of Input During Web Page Generation in Apache Tomcat

23%
Средний
около 3 лет назад
github логотип
GHSA-fj6c-prgj-gr3r

Improper Limitation of a Pathname to a Restricted Directory in Apache Tomcat

0%
Низкий
около 3 лет назад

Уязвимостей на страницу