Логотип exploitDog
bind:"CVE-2008-2938" OR bind:"CVE-2008-1947" OR bind:"CVE-2008-2370" OR bind:"CVE-2008-1232"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2008-2938" OR bind:"CVE-2008-1947" OR bind:"CVE-2008-2370" OR bind:"CVE-2008-1232"

Количество 21

Количество 21

oracle-oval логотип

ELSA-2008-0648

больше 17 лет назад

ELSA-2008-0648: tomcat security update (IMPORTANT)

EPSS: Низкий
ubuntu логотип

CVE-2008-2938

больше 17 лет назад

Directory traversal vulnerability in Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16, when allowLinking and UTF-8 are enabled, allows remote attackers to read arbitrary files via encoded directory traversal sequences in the URI, a different vulnerability than CVE-2008-2370. NOTE: versions earlier than 6.0.18 were reported affected, but the vendor advisory lists 6.0.16 as the last affected version.

CVSS2: 4.3
EPSS: Критический
redhat логотип

CVE-2008-2938

больше 17 лет назад

Directory traversal vulnerability in Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16, when allowLinking and UTF-8 are enabled, allows remote attackers to read arbitrary files via encoded directory traversal sequences in the URI, a different vulnerability than CVE-2008-2370. NOTE: versions earlier than 6.0.18 were reported affected, but the vendor advisory lists 6.0.16 as the last affected version.

EPSS: Критический
nvd логотип

CVE-2008-2938

больше 17 лет назад

Directory traversal vulnerability in Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16, when allowLinking and UTF-8 are enabled, allows remote attackers to read arbitrary files via encoded directory traversal sequences in the URI, a different vulnerability than CVE-2008-2370. NOTE: versions earlier than 6.0.18 were reported affected, but the vendor advisory lists 6.0.16 as the last affected version.

CVSS2: 4.3
EPSS: Критический
debian логотип

CVE-2008-2938

больше 17 лет назад

Directory traversal vulnerability in Apache Tomcat 4.1.0 through 4.1.3 ...

CVSS2: 4.3
EPSS: Критический
github логотип

GHSA-m7xj-ccqc-p4g2

почти 4 года назад

Apache Tomcat Directory Traversal vulnerability

EPSS: Критический
ubuntu логотип

CVE-2008-1947

больше 17 лет назад

Cross-site scripting (XSS) vulnerability in Apache Tomcat 5.5.9 through 5.5.26 and 6.0.0 through 6.0.16 allows remote attackers to inject arbitrary web script or HTML via the name parameter (aka the hostname attribute) to host-manager/html/add.

CVSS2: 4.3
EPSS: Средний
redhat логотип

CVE-2008-1947

больше 17 лет назад

Cross-site scripting (XSS) vulnerability in Apache Tomcat 5.5.9 through 5.5.26 and 6.0.0 through 6.0.16 allows remote attackers to inject arbitrary web script or HTML via the name parameter (aka the hostname attribute) to host-manager/html/add.

EPSS: Средний
nvd логотип

CVE-2008-1947

больше 17 лет назад

Cross-site scripting (XSS) vulnerability in Apache Tomcat 5.5.9 through 5.5.26 and 6.0.0 through 6.0.16 allows remote attackers to inject arbitrary web script or HTML via the name parameter (aka the hostname attribute) to host-manager/html/add.

CVSS2: 4.3
EPSS: Средний
debian логотип

CVE-2008-1947

больше 17 лет назад

Cross-site scripting (XSS) vulnerability in Apache Tomcat 5.5.9 throug ...

CVSS2: 4.3
EPSS: Средний
github логотип

GHSA-f98p-9pp6-7q6c

почти 4 года назад

Apache Tomcat Cross-site scripting (XSS) vulnerability

EPSS: Средний
ubuntu логотип

CVE-2008-2370

больше 17 лет назад

Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16, when a RequestDispatcher is used, performs path normalization before removing the query string from the URI, which allows remote attackers to conduct directory traversal attacks and read arbitrary files via a .. (dot dot) in a request parameter.

CVSS2: 5
EPSS: Высокий
redhat логотип

CVE-2008-2370

больше 17 лет назад

Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16, when a RequestDispatcher is used, performs path normalization before removing the query string from the URI, which allows remote attackers to conduct directory traversal attacks and read arbitrary files via a .. (dot dot) in a request parameter.

EPSS: Высокий
nvd логотип

CVE-2008-2370

больше 17 лет назад

Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16, when a RequestDispatcher is used, performs path normalization before removing the query string from the URI, which allows remote attackers to conduct directory traversal attacks and read arbitrary files via a .. (dot dot) in a request parameter.

CVSS2: 5
EPSS: Высокий
debian логотип

CVE-2008-2370

больше 17 лет назад

Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 th ...

CVSS2: 5
EPSS: Высокий
ubuntu логотип

CVE-2008-1232

больше 17 лет назад

Cross-site scripting (XSS) vulnerability in Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16 allows remote attackers to inject arbitrary web script or HTML via a crafted string that is used in the message argument to the HttpServletResponse.sendError method.

CVSS2: 4.3
EPSS: Средний
redhat логотип

CVE-2008-1232

больше 17 лет назад

Cross-site scripting (XSS) vulnerability in Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16 allows remote attackers to inject arbitrary web script or HTML via a crafted string that is used in the message argument to the HttpServletResponse.sendError method.

EPSS: Средний
nvd логотип

CVE-2008-1232

больше 17 лет назад

Cross-site scripting (XSS) vulnerability in Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16 allows remote attackers to inject arbitrary web script or HTML via a crafted string that is used in the message argument to the HttpServletResponse.sendError method.

CVSS2: 4.3
EPSS: Средний
debian логотип

CVE-2008-1232

больше 17 лет назад

Cross-site scripting (XSS) vulnerability in Apache Tomcat 4.1.0 throug ...

CVSS2: 4.3
EPSS: Средний
github логотип

GHSA-q74x-qqhr-f8rx

почти 4 года назад

Apache Tomcat Cross-site scripting (XSS) vulnerability

EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
oracle-oval логотип
ELSA-2008-0648

ELSA-2008-0648: tomcat security update (IMPORTANT)

больше 17 лет назад
ubuntu логотип
CVE-2008-2938

Directory traversal vulnerability in Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16, when allowLinking and UTF-8 are enabled, allows remote attackers to read arbitrary files via encoded directory traversal sequences in the URI, a different vulnerability than CVE-2008-2370. NOTE: versions earlier than 6.0.18 were reported affected, but the vendor advisory lists 6.0.16 as the last affected version.

CVSS2: 4.3
93%
Критический
больше 17 лет назад
redhat логотип
CVE-2008-2938

Directory traversal vulnerability in Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16, when allowLinking and UTF-8 are enabled, allows remote attackers to read arbitrary files via encoded directory traversal sequences in the URI, a different vulnerability than CVE-2008-2370. NOTE: versions earlier than 6.0.18 were reported affected, but the vendor advisory lists 6.0.16 as the last affected version.

93%
Критический
больше 17 лет назад
nvd логотип
CVE-2008-2938

Directory traversal vulnerability in Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16, when allowLinking and UTF-8 are enabled, allows remote attackers to read arbitrary files via encoded directory traversal sequences in the URI, a different vulnerability than CVE-2008-2370. NOTE: versions earlier than 6.0.18 were reported affected, but the vendor advisory lists 6.0.16 as the last affected version.

CVSS2: 4.3
93%
Критический
больше 17 лет назад
debian логотип
CVE-2008-2938

Directory traversal vulnerability in Apache Tomcat 4.1.0 through 4.1.3 ...

CVSS2: 4.3
93%
Критический
больше 17 лет назад
github логотип
GHSA-m7xj-ccqc-p4g2

Apache Tomcat Directory Traversal vulnerability

93%
Критический
почти 4 года назад
ubuntu логотип
CVE-2008-1947

Cross-site scripting (XSS) vulnerability in Apache Tomcat 5.5.9 through 5.5.26 and 6.0.0 through 6.0.16 allows remote attackers to inject arbitrary web script or HTML via the name parameter (aka the hostname attribute) to host-manager/html/add.

CVSS2: 4.3
59%
Средний
больше 17 лет назад
redhat логотип
CVE-2008-1947

Cross-site scripting (XSS) vulnerability in Apache Tomcat 5.5.9 through 5.5.26 and 6.0.0 through 6.0.16 allows remote attackers to inject arbitrary web script or HTML via the name parameter (aka the hostname attribute) to host-manager/html/add.

59%
Средний
больше 17 лет назад
nvd логотип
CVE-2008-1947

Cross-site scripting (XSS) vulnerability in Apache Tomcat 5.5.9 through 5.5.26 and 6.0.0 through 6.0.16 allows remote attackers to inject arbitrary web script or HTML via the name parameter (aka the hostname attribute) to host-manager/html/add.

CVSS2: 4.3
59%
Средний
больше 17 лет назад
debian логотип
CVE-2008-1947

Cross-site scripting (XSS) vulnerability in Apache Tomcat 5.5.9 throug ...

CVSS2: 4.3
59%
Средний
больше 17 лет назад
github логотип
GHSA-f98p-9pp6-7q6c

Apache Tomcat Cross-site scripting (XSS) vulnerability

59%
Средний
почти 4 года назад
ubuntu логотип
CVE-2008-2370

Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16, when a RequestDispatcher is used, performs path normalization before removing the query string from the URI, which allows remote attackers to conduct directory traversal attacks and read arbitrary files via a .. (dot dot) in a request parameter.

CVSS2: 5
89%
Высокий
больше 17 лет назад
redhat логотип
CVE-2008-2370

Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16, when a RequestDispatcher is used, performs path normalization before removing the query string from the URI, which allows remote attackers to conduct directory traversal attacks and read arbitrary files via a .. (dot dot) in a request parameter.

89%
Высокий
больше 17 лет назад
nvd логотип
CVE-2008-2370

Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16, when a RequestDispatcher is used, performs path normalization before removing the query string from the URI, which allows remote attackers to conduct directory traversal attacks and read arbitrary files via a .. (dot dot) in a request parameter.

CVSS2: 5
89%
Высокий
больше 17 лет назад
debian логотип
CVE-2008-2370

Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 th ...

CVSS2: 5
89%
Высокий
больше 17 лет назад
ubuntu логотип
CVE-2008-1232

Cross-site scripting (XSS) vulnerability in Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16 allows remote attackers to inject arbitrary web script or HTML via a crafted string that is used in the message argument to the HttpServletResponse.sendError method.

CVSS2: 4.3
38%
Средний
больше 17 лет назад
redhat логотип
CVE-2008-1232

Cross-site scripting (XSS) vulnerability in Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16 allows remote attackers to inject arbitrary web script or HTML via a crafted string that is used in the message argument to the HttpServletResponse.sendError method.

38%
Средний
больше 17 лет назад
nvd логотип
CVE-2008-1232

Cross-site scripting (XSS) vulnerability in Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16 allows remote attackers to inject arbitrary web script or HTML via a crafted string that is used in the message argument to the HttpServletResponse.sendError method.

CVSS2: 4.3
38%
Средний
больше 17 лет назад
debian логотип
CVE-2008-1232

Cross-site scripting (XSS) vulnerability in Apache Tomcat 4.1.0 throug ...

CVSS2: 4.3
38%
Средний
больше 17 лет назад
github логотип
GHSA-q74x-qqhr-f8rx

Apache Tomcat Cross-site scripting (XSS) vulnerability

38%
Средний
почти 4 года назад

Уязвимостей на страницу