Логотип exploitDog
bind:"CVE-2011-0013" OR bind:"CVE-2010-4172" OR bind:"CVE-2010-3718"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2011-0013" OR bind:"CVE-2010-4172" OR bind:"CVE-2010-3718"

Количество 17

Количество 17

oracle-oval логотип

ELSA-2011-0791

больше 14 лет назад

ELSA-2011-0791: tomcat6 security and bug fix update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2011-1845

почти 14 лет назад

ELSA-2011-1845: tomcat5 security update (MODERATE)

EPSS: Низкий
ubuntu логотип

CVE-2011-0013

больше 14 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the HTML Manager Interface in Apache Tomcat 5.5 before 5.5.32, 6.0 before 6.0.30, and 7.0 before 7.0.6 allow remote attackers to inject arbitrary web script or HTML, as demonstrated via the display-name tag.

CVSS2: 4.3
EPSS: Средний
redhat логотип

CVE-2011-0013

почти 15 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the HTML Manager Interface in Apache Tomcat 5.5 before 5.5.32, 6.0 before 6.0.30, and 7.0 before 7.0.6 allow remote attackers to inject arbitrary web script or HTML, as demonstrated via the display-name tag.

CVSS2: 4.3
EPSS: Средний
nvd логотип

CVE-2011-0013

больше 14 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the HTML Manager Interface in Apache Tomcat 5.5 before 5.5.32, 6.0 before 6.0.30, and 7.0 before 7.0.6 allow remote attackers to inject arbitrary web script or HTML, as demonstrated via the display-name tag.

CVSS2: 4.3
EPSS: Средний
debian логотип

CVE-2011-0013

больше 14 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the HTML Manage ...

CVSS2: 4.3
EPSS: Средний
github логотип

GHSA-3p86-xgrq-m6p6

больше 3 лет назад

Improper Neutralization of Input During Web Page Generation in Apache Tomcat

EPSS: Средний
ubuntu логотип

CVE-2010-4172

почти 15 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the Manager application in Apache Tomcat 6.0.12 through 6.0.29 and 7.0.0 through 7.0.4 allow remote attackers to inject arbitrary web script or HTML via the (1) orderBy or (2) sort parameter to sessionsList.jsp, or unspecified input to (3) sessionDetail.jsp or (4) java/org/apache/catalina/manager/JspHelper.java, related to use of untrusted web applications.

CVSS2: 4.3
EPSS: Средний
redhat логотип

CVE-2010-4172

почти 15 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the Manager application in Apache Tomcat 6.0.12 through 6.0.29 and 7.0.0 through 7.0.4 allow remote attackers to inject arbitrary web script or HTML via the (1) orderBy or (2) sort parameter to sessionsList.jsp, or unspecified input to (3) sessionDetail.jsp or (4) java/org/apache/catalina/manager/JspHelper.java, related to use of untrusted web applications.

CVSS2: 4.3
EPSS: Средний
nvd логотип

CVE-2010-4172

почти 15 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the Manager application in Apache Tomcat 6.0.12 through 6.0.29 and 7.0.0 through 7.0.4 allow remote attackers to inject arbitrary web script or HTML via the (1) orderBy or (2) sort parameter to sessionsList.jsp, or unspecified input to (3) sessionDetail.jsp or (4) java/org/apache/catalina/manager/JspHelper.java, related to use of untrusted web applications.

CVSS2: 4.3
EPSS: Средний
debian логотип

CVE-2010-4172

почти 15 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the Manager app ...

CVSS2: 4.3
EPSS: Средний
ubuntu логотип

CVE-2010-3718

больше 14 лет назад

Apache Tomcat 7.0.0 through 7.0.3, 6.0.x, and 5.5.x, when running within a SecurityManager, does not make the ServletContext attribute read-only, which allows local web applications to read or write files outside of the intended working directory, as demonstrated using a directory traversal attack.

CVSS2: 1.2
EPSS: Низкий
redhat логотип

CVE-2010-3718

почти 15 лет назад

Apache Tomcat 7.0.0 through 7.0.3, 6.0.x, and 5.5.x, when running within a SecurityManager, does not make the ServletContext attribute read-only, which allows local web applications to read or write files outside of the intended working directory, as demonstrated using a directory traversal attack.

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2010-3718

больше 14 лет назад

Apache Tomcat 7.0.0 through 7.0.3, 6.0.x, and 5.5.x, when running within a SecurityManager, does not make the ServletContext attribute read-only, which allows local web applications to read or write files outside of the intended working directory, as demonstrated using a directory traversal attack.

CVSS2: 1.2
EPSS: Низкий
debian логотип

CVE-2010-3718

больше 14 лет назад

Apache Tomcat 7.0.0 through 7.0.3, 6.0.x, and 5.5.x, when running with ...

CVSS2: 1.2
EPSS: Низкий
github логотип

GHSA-c78g-qwpw-2jgv

больше 3 лет назад

Improper Neutralization of Input During Web Page Generation in Apache Tomcat

EPSS: Средний
github логотип

GHSA-fj6c-prgj-gr3r

больше 3 лет назад

Improper Limitation of a Pathname to a Restricted Directory in Apache Tomcat

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
oracle-oval логотип
ELSA-2011-0791

ELSA-2011-0791: tomcat6 security and bug fix update (MODERATE)

больше 14 лет назад
oracle-oval логотип
ELSA-2011-1845

ELSA-2011-1845: tomcat5 security update (MODERATE)

почти 14 лет назад
ubuntu логотип
CVE-2011-0013

Multiple cross-site scripting (XSS) vulnerabilities in the HTML Manager Interface in Apache Tomcat 5.5 before 5.5.32, 6.0 before 6.0.30, and 7.0 before 7.0.6 allow remote attackers to inject arbitrary web script or HTML, as demonstrated via the display-name tag.

CVSS2: 4.3
32%
Средний
больше 14 лет назад
redhat логотип
CVE-2011-0013

Multiple cross-site scripting (XSS) vulnerabilities in the HTML Manager Interface in Apache Tomcat 5.5 before 5.5.32, 6.0 before 6.0.30, and 7.0 before 7.0.6 allow remote attackers to inject arbitrary web script or HTML, as demonstrated via the display-name tag.

CVSS2: 4.3
32%
Средний
почти 15 лет назад
nvd логотип
CVE-2011-0013

Multiple cross-site scripting (XSS) vulnerabilities in the HTML Manager Interface in Apache Tomcat 5.5 before 5.5.32, 6.0 before 6.0.30, and 7.0 before 7.0.6 allow remote attackers to inject arbitrary web script or HTML, as demonstrated via the display-name tag.

CVSS2: 4.3
32%
Средний
больше 14 лет назад
debian логотип
CVE-2011-0013

Multiple cross-site scripting (XSS) vulnerabilities in the HTML Manage ...

CVSS2: 4.3
32%
Средний
больше 14 лет назад
github логотип
GHSA-3p86-xgrq-m6p6

Improper Neutralization of Input During Web Page Generation in Apache Tomcat

32%
Средний
больше 3 лет назад
ubuntu логотип
CVE-2010-4172

Multiple cross-site scripting (XSS) vulnerabilities in the Manager application in Apache Tomcat 6.0.12 through 6.0.29 and 7.0.0 through 7.0.4 allow remote attackers to inject arbitrary web script or HTML via the (1) orderBy or (2) sort parameter to sessionsList.jsp, or unspecified input to (3) sessionDetail.jsp or (4) java/org/apache/catalina/manager/JspHelper.java, related to use of untrusted web applications.

CVSS2: 4.3
30%
Средний
почти 15 лет назад
redhat логотип
CVE-2010-4172

Multiple cross-site scripting (XSS) vulnerabilities in the Manager application in Apache Tomcat 6.0.12 through 6.0.29 and 7.0.0 through 7.0.4 allow remote attackers to inject arbitrary web script or HTML via the (1) orderBy or (2) sort parameter to sessionsList.jsp, or unspecified input to (3) sessionDetail.jsp or (4) java/org/apache/catalina/manager/JspHelper.java, related to use of untrusted web applications.

CVSS2: 4.3
30%
Средний
почти 15 лет назад
nvd логотип
CVE-2010-4172

Multiple cross-site scripting (XSS) vulnerabilities in the Manager application in Apache Tomcat 6.0.12 through 6.0.29 and 7.0.0 through 7.0.4 allow remote attackers to inject arbitrary web script or HTML via the (1) orderBy or (2) sort parameter to sessionsList.jsp, or unspecified input to (3) sessionDetail.jsp or (4) java/org/apache/catalina/manager/JspHelper.java, related to use of untrusted web applications.

CVSS2: 4.3
30%
Средний
почти 15 лет назад
debian логотип
CVE-2010-4172

Multiple cross-site scripting (XSS) vulnerabilities in the Manager app ...

CVSS2: 4.3
30%
Средний
почти 15 лет назад
ubuntu логотип
CVE-2010-3718

Apache Tomcat 7.0.0 through 7.0.3, 6.0.x, and 5.5.x, when running within a SecurityManager, does not make the ServletContext attribute read-only, which allows local web applications to read or write files outside of the intended working directory, as demonstrated using a directory traversal attack.

CVSS2: 1.2
0%
Низкий
больше 14 лет назад
redhat логотип
CVE-2010-3718

Apache Tomcat 7.0.0 through 7.0.3, 6.0.x, and 5.5.x, when running within a SecurityManager, does not make the ServletContext attribute read-only, which allows local web applications to read or write files outside of the intended working directory, as demonstrated using a directory traversal attack.

CVSS2: 4
0%
Низкий
почти 15 лет назад
nvd логотип
CVE-2010-3718

Apache Tomcat 7.0.0 through 7.0.3, 6.0.x, and 5.5.x, when running within a SecurityManager, does not make the ServletContext attribute read-only, which allows local web applications to read or write files outside of the intended working directory, as demonstrated using a directory traversal attack.

CVSS2: 1.2
0%
Низкий
больше 14 лет назад
debian логотип
CVE-2010-3718

Apache Tomcat 7.0.0 through 7.0.3, 6.0.x, and 5.5.x, when running with ...

CVSS2: 1.2
0%
Низкий
больше 14 лет назад
github логотип
GHSA-c78g-qwpw-2jgv

Improper Neutralization of Input During Web Page Generation in Apache Tomcat

30%
Средний
больше 3 лет назад
github логотип
GHSA-fj6c-prgj-gr3r

Improper Limitation of a Pathname to a Restricted Directory in Apache Tomcat

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу