|
|
Info |
Last Modified |
| 10 months ago |
|
|
|
|
|
Description |
Apache Tomcat contains a flaw that allows a remote cross site scripting attack. This flaw exists because the Manager and Host Manager applications do not validate the filename of files uploaded via the /manager/html/upload utility. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
|
Classification |
Location:
Remote/Network Access Required
Attack Type:
Input Manipulation
Impact:
Loss of Integrity
Exploit:
Exploit Unknown
Disclosure:
OSVDB Verified
OSVDB:
Web Related
|
|
Technical |
An attacker must supply valid authentication credentials in order to exploit this vulnerability.
|
|
Solution |
Currently, there are no known upgrades, patches, or workarounds available to correct this issue. However, some vendors have released patches for some older versions.
|
|
Products |
|
Tomcat
 |
4.0.3 |
4.1.24 |
4.0.2 |
4.0 |
4.0.2-b2 |
4.0.4 |
4.0.5 |
4.0.6 |
4.1.10 |
4.1.12 |
4.1.18 |
4.1.19 |
4.1.20 |
4.1.21 |
4.1.22 |
4.1.23 |
4.1.26 |
4.1.27 |
4.1.28-alpha |
4.1.29-alpha |
4.1.29 |
4.1.30-alpha |
4.1.30 |
4.1.31 |
4.1.32 |
4.1.34 |
4.1.36 |
5.0.0 |
5.0.1 |
5.0.10-alpha |
5.0.11-alpha |
5.0.12-alpha |
5.0.12-beta |
5.0.13-alpha |
5.0.14-alpha |
5.0.14-beta |
5.0.15-alpha |
5.0.16-alpha |
5.0.16 |
5.0.17-alpha |
5.0.18-alpha |
5.0.18 |
5.0.19-alpha |
5.0.19 |
5.0.2 |
5.0.2-alpha |
5.0.21-alpha |
5.0.22-alpha |
5.0.23-alpha |
5.0.24 |
5.0.25 |
5.0.26-beta |
5.0.27 |
5.0.29 |
5.0.3 |
5.0.4 |
5.0.5 |
5.0.6-alpha |
5.0.7-alpha |
5.0.8-alpha |
5.0.9-alpha |
5.0.9-beta |
5.5.0 |
5.5.1 |
5.5.10 |
5.5.11 |
5.5.13-beta |
5.5.13 |
5.5.14-beta |
5.5.14 |
5.5.15-beta |
5.5.15 |
5.5.2 |
5.5.3 |
5.5.4 |
5.5.5 |
5.5.6 |
5.5.7 |
5.5.8 |
5.5.9 |
5.0.28 |
5.0.30-beta |
5.0.30 |
5.5.12 |
5.5.16-beta |
5.5.16 |
5.5.17-beta |
5.5.17 |
5.5.20 |
5.5.23 |
6.0.0-alpha |
6.0.0 |
6.0.1-alpha |
6.0.1 |
6.0.10 |
6.0.13 |
6.0.2-alpha |
6.0.2-beta |
6.0.4-alpha |
6.0.4 |
6.0.6-alpha |
6.0.6 |
6.0.7-alpha |
6.0.7-beta |
6.0.7 |
6.0.8-alpha |
6.0.8 |
6.0.9-alpha |
6.0.9-beta |
6.0.9 |
|
|
|
|
|
|
Credit |
- Daiki Fukumori - Secure Sky Technology, Inc.
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|