Apache Tomcat SendMailServlet Cross-Site Scripting Vulnerability
BID:24999
Info
Apache Tomcat SendMailServlet Cross-Site Scripting Vulnerability
| Bugtraq ID: | 24999 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-3383 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 21 2007 12:00AM |
| Updated: | Jul 01 2008 12:40AM |
| Credit: | Tomasz Kuczynski is credited with the discovery of this vulnerability. |
| Vulnerable: |
Apple Mac OS X Server 10.4.11 Apple Mac OS X Server 10.4.10 Apple Mac OS X Server 10.4.9 Apple Mac OS X Server 10.4.8 Apple Mac OS X Server 10.4.7 Apple Mac OS X Server 10.4.6 Apple Mac OS X Server 10.4.5 Apple Mac OS X Server 10.4.4 Apple Mac OS X Server 10.4.3 Apple Mac OS X Server 10.4.2 Apple Mac OS X Server 10.4.1 Apple Mac OS X Server 10.4 Apple Mac OS X 10.4.11 Apple Mac OS X 10.4.10 Apple Mac OS X 10.4.9 Apple Mac OS X 10.4.8 Apple Mac OS X 10.4.7 Apple Mac OS X 10.4.6 Apple Mac OS X 10.4.5 Apple Mac OS X 10.4.4 Apple Mac OS X 10.4.3 Apple Mac OS X 10.4.2 Apple Mac OS X 10.4.1 Apple Mac OS X 10.4 Apache Tomcat 4.1.36 Apache Tomcat 4.1.34 Apache Tomcat 4.1.24 Apache Tomcat 4.1.12 Apache Tomcat 4.1.10 Apache Tomcat 4.1.9 beta Apache Tomcat 4.1.3 beta Apache Tomcat 4.1 Apache Tomcat 4.0.6 Apache Tomcat 4.0.5 Apache Tomcat 4.0.4 Apache Tomcat 4.0.3 Apache Tomcat 4.0.2 Apache Tomcat 4.0.1 Apache Tomcat 4.0 |
| Not Vulnerable: | |
Discussion
Apache Tomcat SendMailServlet Cross-Site Scripting Vulnerability
Apache Tomcat SendMailServlet is prone to a cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
This issue affects the following versions of Tomcat:
4.0.0 to 4.0.6
4.1.0 to 4.1.36
NOTE: Apache Tomcat SendMailServlet is an example application. It is not intended for production environments.
Apache Tomcat SendMailServlet is prone to a cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
This issue affects the following versions of Tomcat:
4.0.0 to 4.0.6
4.1.0 to 4.1.36
NOTE: Apache Tomcat SendMailServlet is an example application. It is not intended for production environments.
Exploit / POC
Apache Tomcat SendMailServlet Cross-Site Scripting Vulnerability
An attacker can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
An attacker can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
Solution / Fix
Apache Tomcat SendMailServlet Cross-Site Scripting Vulnerability
Solution:
This issue has been addressed in Apache Tomcat 4.1.HEAD. Please see the references for more information.
Solution:
This issue has been addressed in Apache Tomcat 4.1.HEAD. Please see the references for more information.
References
Apache Tomcat SendMailServlet Cross-Site Scripting Vulnerability
References:
References:
- About the security content of Security Update 2008-004 and Mac OS X 10.5.4 (Apple)
- Apache Tomcat 4.x vulnerabilities (Apache)
- Apache Tomcat Homepage (Apache)
- CVE-2007-3383: XSS in Tomcat send mail example (Apache)
- CVE-2007-3383: XSS in Tomcat send mail example (Mark Thomas
) - Vulnerability Note VU#862600 Apache Tomcat SendMailServlet example vulnerable to (US-CERT)