[Forgot Password]
Login  Register Subscribe

30480

 
 

423868

 
 

253928

 
 

909

 
 

198006

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2007-2450Date: (C)2007-06-14   (M)2023-12-22


Multiple cross-site scripting (XSS) vulnerabilities in the (1) Manager and (2) Host Manager web applications in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.36, 5.0.0 through 5.0.30, 5.5.0 through 5.5.24, and 6.0.0 through 6.0.13 allow remote authenticated users to inject arbitrary web script or HTML via a parameter name to manager/html/upload, and other unspecified vectors.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 3.5
Exploit Score: 6.8
Impact Score: 2.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: MEDIUM
Authentication: SINGLE
Confidentiality: NONE
Integrity: PARTIAL
Availability: NONE
  
Reference:
SECTRACK-1018245
http://www.securityfocus.com/archive/1/471357/100/0/threaded
http://www.securityfocus.com/archive/1/500396/100/0/threaded
http://www.securityfocus.com/archive/1/500412/100/0/threaded
SUNALERT-239312
BID-24475
SECUNIA-25678
SECUNIA-26076
SECUNIA-27037
SECUNIA-27727
SREASON-2813
SECUNIA-28549
SECUNIA-30802
SECUNIA-30899
SECUNIA-30908
SECUNIA-33668
OSVDB-36079
ADV-2007-2213
ADV-2007-3386
ADV-2008-1979
ADV-2008-1981
ADV-2009-0233
APPLE-SA-2008-06-30
DSA-1468
FEDORA-2007-3456
JVN#07100457
MDKSA-2007:241
RHSA-2007:0569
RHSA-2008:0261
SSRT071447
SUSE-SR:2009:004
https://lists.apache.org/thread.html/29dc6c2b625789e70a9c4756b5a327e6547273ff8bde7e0327af48c5%40%3Cdev.tomcat.apache.org%3E
https://lists.apache.org/thread.html/c62b0e3a7bf23342352a5810c640a94b6db69957c5c19db507004d74%40%3Cdev.tomcat.apache.org%3E
https://lists.apache.org/thread.html/rb71997f506c6cc8b530dd845c084995a9878098846c7b4eacfae8db3%40%3Cdev.tomcat.apache.org%3E
http://community.ca.com/blogs/casecurityresponseblog/archive/2009/01/23.aspx
http://support.apple.com/kb/HT2163
http://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=197540
http://tomcat.apache.org/security-4.html
http://tomcat.apache.org/security-5.html
http://tomcat.apache.org/security-6.html
oval:org.mitre.oval:def:11287
tomcat-hostmanager-xss(34868)

CPE    88
cpe:/a:apache:tomcat:5.5.3
cpe:/a:apache:tomcat:5.0.12
cpe:/a:apache:tomcat:5.5.2
cpe:/a:apache:tomcat:5.0.13
...
CWE    1
CWE-79
OVAL    1
oval:org.mitre.oval:def:7601

© SecPod Technologies