|
|
| |
Credit:
The information has been provided by Mark Thomas.
The original article can be found at: http://tomcat.apache.org/security-6.html
|
| |
Vulnerable Systems:
* Tomcat versions from 4.0.0 to 4.0.6
* Tomcat versions from 4.1.0 to 4.1.36
* Tomcat versions from 5.0.0 to 5.0.30
* Tomcat versions from 5.5.0 to 5.5.23
* Tomcat versions from 6.0.0 to 6.0.10
Immune Systems:
* Tomcat version 4.0.7
* Tomcat version 4.1.37
* Tomcat version 5.0.31
* Tomcat version 5.5.24
* Tomcat version 6.0.11
The JSP and Servlet included in the sample application within the Tomcat documentation webapp did not escape user provided data before including it in the output. This enabled a XSS attack. These pages have been simplified not to use any user provided data in the output.
Example:
http://server/tomcat-docs/appdev/sample/web/hello.jsp?test=<script>alert(document.domain)</script>
CVE Information:
CVE-2007-1355
|
|
|