GHSA-4c6x-gfc8-c26r
Dashboard / Vulnerabilities / GHSA-4c6x-gfc8-c26r
Summary: Apache Tomcat Vulnerable to Cross-Site Scripting
Details: Multiple cross-site scripting (XSS) vulnerabilities in the appdev/sample/web/hello.jsp example application in Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.36, 5.0.0 through 5.0.30, 5.5.0 through 5.5.23, and 6.0.0 through 6.0.10 allow remote attackers to inject arbitrary web script or HTML via the test parameter and unspecified vectors.
References: https://nvd.nist.gov/vuln/detail/CVE-2007-1355, https://exchange.xforce.ibmcloud.com/vulnerabilities/34377, https://github.com/apache/tomcat, https://lists.apache.org/thread.html/29dc6c2b625789e70a9c4756b5a327e6547273ff8bde7e0327af48c5%40%3Cdev.tomcat.apache.org%3E, https://lists.apache.org/thread.html/29dc6c2b625789e70a9c4756b5a327e6547273ff8bde7e0327af48c5@%3Cdev.tomcat.apache.org%3E, https://lists.apache.org/thread.html/c62b0e3a7bf23342352a5810c640a94b6db69957c5c19db507004d74%40%3Cdev.tomcat.apache.org%3E, https://lists.apache.org/thread.html/c62b0e3a7bf23342352a5810c640a94b6db69957c5c19db507004d74@%3Cdev.tomcat.apache.org%3E, https://lists.apache.org/thread.html/rb71997f506c6cc8b530dd845c084995a9878098846c7b4eacfae8db3%40%3Cdev.tomcat.apache.org%3E, https://lists.apache.org/thread.html/rb71997f506c6cc8b530dd845c084995a9878098846c7b4eacfae8db3@%3Cdev.tomcat.apache.org%3E, https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6111, https://www.redhat.com/archives/fedora-package-announce/2007-November/msg00525.html, http://community.ca.com/blogs/casecurityresponseblog/archive/2009/01/23.aspx, http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01178795, http://lists.apple.com/archives/security-announce/2008//Jun/msg00002.html, http://rhn.redhat.com/errata/RHSA-2008-0630.html, http://sunsolve.sun.com/search/document.do?assetkey=1-26-239312-1, http://support.apple.com/kb/HT2163, http://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=197540, http://tomcat.apache.org/security-4.html, http://tomcat.apache.org/security-5.html, http://tomcat.apache.org/security-6.html, http://www.redhat.com/support/errata/RHSA-2008-0261.html
Affected packages
Package
Name: org.apache.tomcat:jsp-api
Purl: pkg:maven/org.apache.tomcat/jsp-api
Affected ranges
Type: ECOSYSTEM
Events:
