Apache Tomcat Manager and Host Manager Upload Script Cross-Site Scripting Vulnerability
BID:24475
Info
Apache Tomcat Manager and Host Manager Upload Script Cross-Site Scripting Vulnerability
| Bugtraq ID: | 24475 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-2450 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 12 2007 12:00AM |
| Updated: | Jul 06 2010 06:48PM |
| Credit: | Daiki Fukumori is credited with the discovery of this vulnerability. |
| Vulnerable: |
SuSE SUSE Linux Enterprise Server 10 SP2 Sun Solaris 9_x86 Sun Solaris 9_sparc Sun Solaris 10_x86 Sun Solaris 10_sparc Redhat Red Hat Network Satellite Server 5.0 Redhat Network Satellite (for RHEL 4) 4.2 Redhat Network Satellite (for RHEL 3) 4.2 Redhat Fedora 7 Redhat Enterprise Linux Desktop Workstation 5 client Redhat Enterprise Linux Desktop 5 client Redhat Enterprise Linux 5 Server Novell ZENworks Linux Management 7.3 Mandriva Linux Mandrake 2008.0 x86_64 Mandriva Linux Mandrake 2008.0 Mandriva Linux Mandrake 2007.1 x86_64 Mandriva Linux Mandrake 2007.1 HP HP-UX B.11.31 HP HP-UX B.11.23 HP HP-UX B.11.11 Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 Computer Associates Cohesion Application Configuration Manager 4.5 Apple Mac OS X Server 10.5.3 Apple Mac OS X Server 10.5.2 Apple Mac OS X Server 10.5.1 Apple Mac OS X Server 10.4.11 Apple Mac OS X Server 10.5 Apple Mac OS X 10.5.3 Apple Mac OS X 10.5.2 Apple Mac OS X 10.5.1 Apple Mac OS X 10.4.11 Apple Mac OS X 10.5 Apache Tomcat 6.0.13 Apache Tomcat 6.0.12 Apache Tomcat 6.0.11 Apache Tomcat 6.0.10 Apache Tomcat 6.0.9 Apache Tomcat 6.0.8 Apache Tomcat 6.0.7 Apache Tomcat 6.0.6 Apache Tomcat 6.0.5 Apache Tomcat 6.0.4 Apache Tomcat 6.0.3 Apache Tomcat 6.0.2 Apache Tomcat 6.0.1 Apache Tomcat 5.5.24 Apache Tomcat 5.5.23 Apache Tomcat 5.5.22 Apache Tomcat 5.5.21 Apache Tomcat 5.5.20 Apache Tomcat 5.5.19 Apache Tomcat 5.5.18 Apache Tomcat 5.5.17 Apache Tomcat 5.5.16 Apache Tomcat 5.5.15 Apache Tomcat 5.5.14 Apache Tomcat 5.5.13 Apache Tomcat 5.5.12 Apache Tomcat 5.5.11 Apache Tomcat 5.5.10 Apache Tomcat 5.5.2 Apache Tomcat 5.5.1 Apache Tomcat 5.5 Apache Tomcat 5.0.30 Apache Tomcat 5.0.16 Apache Tomcat 5.0.15 Apache Tomcat 5.0.14 Apache Tomcat 5.0.13 Apache Tomcat 5.0.12 Apache Tomcat 5.0.11 Apache Tomcat 5.0.10 Apache Tomcat 5.0.3 Apache Tomcat 5.0.2 Apache Tomcat 5.0.1 Apache Tomcat 4.1.36 Apache Tomcat 4.1 Apache Tomcat 4.0.6 Apache Tomcat 4.0.5 Apache Tomcat 4.0.4 Apache Tomcat 4.0.3 Apache Tomcat 4.0.2 Apache Tomcat 4.0.1 Apache Tomcat 4.0 Apache Tomcat 5.0 |
| Not Vulnerable: |
Computer Associates Cohesion Application Configuration Manager 4.5 SP1 Apple Mac OS X Server 10.5.4 Apple Mac OS X 10.5.4 |
Discussion
Apache Tomcat Manager and Host Manager Upload Script Cross-Site Scripting Vulnerability
Apache Tomcat Manager and Host Manager are prone to a cross-site scripting vulnerability because the applications fail to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Apache Tomcat Manager and Host Manager are prone to a cross-site scripting vulnerability because the applications fail to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Exploit / POC
Apache Tomcat Manager and Host Manager Upload Script Cross-Site Scripting Vulnerability
An attacker can trigger this vulnerability by enticing a victim to follow a malicious URI.
An attacker can trigger this vulnerability by enticing a victim to follow a malicious URI.
Solution / Fix
Apache Tomcat Manager and Host Manager Upload Script Cross-Site Scripting Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Apache Tomcat Manager and Host Manager Upload Script Cross-Site Scripting Vulnerability
References:
References:
- About the security content of Security Update 2008-004 and Mac OS X 10.5.4 (Apple)
- Tomcat Homepage (Apache Software Foundation)
- ZLM 7.3 IR3 Tomcat 5.0.30 to fix reported security vulnerabilities (Novell)
- [CVE-2007-2450]: Apache Tomcat XSS vulnerability in Manager (Mark Thomas
) - CA20090123-01: Cohesion Tomcat Multiple Vulnerabilities (Updated - v1.1) ("Williams, James K"
) - CA20090123-01: Security Notice for Cohesion Tomcat (Computer Associates)
- RHSA-2007:0569-2: Moderate: tomcat security update (Red Hat)
- RHSA-2008:0261-4 Moderate: Red Hat Network Satellite Server security update (Red Hat)
- RHSA-2008:0524-4 Red Hat Network Satellite Server security update (Red Hat)
- Security Vulnerabilities in Tomcat 4.0 Shipped with Solaris 9 and 10 (Sun Microsystems)
- Solution 239312 : Security Vulnerabilities in Tomcat 4.0 Shipped with Solaris (Sun)
- Tomcat 5.0.28 in ZLM 7.3 subject to "Multiple Vendor Multiple HTTP Request Smugg (Novell)
- Tomcat 5.0.28 in ZLM 7.3 subject to Multiple Vendor Multiple HTTP Request Smuggl (Novell)