Apache Tomcat Error Message Reporting Cross Site Scripting Vulnerability
BID:25174
Info
Apache Tomcat Error Message Reporting Cross Site Scripting Vulnerability
| Bugtraq ID: | 25174 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-3384 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 02 2007 12:00AM |
| Updated: | Aug 02 2007 11:45PM |
| Credit: | Tomasz Kuczynski, Poznan Supercomputing, and Networking Center are credited with the discovery of this vulnerability. |
| Vulnerable: |
Apache Tomcat 3.3.2 Apache Tomcat 3.3.1 a Apache Tomcat 3.3.1 Apache Tomcat 3.3 |
| Not Vulnerable: | |
Discussion
Apache Tomcat Error Message Reporting Cross Site Scripting Vulnerability
Apache Tomcat is prone to a cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to inject HTML and script code into the browser of an unsuspecting victim. The attacker may then steal cookie-based authentication credentials and launch other attacks.
This issue affects Tomcat 3.3 to 3.3.2.
Apache Tomcat is prone to a cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to inject HTML and script code into the browser of an unsuspecting victim. The attacker may then steal cookie-based authentication credentials and launch other attacks.
This issue affects Tomcat 3.3 to 3.3.2.
Exploit / POC
Apache Tomcat Error Message Reporting Cross Site Scripting Vulnerability
To exploit this issue, an attacker must entice an unsuspecting victim into visiting an attacker-controlled webpage consisting of malicious POST data.
To exploit this issue, an attacker must entice an unsuspecting victim into visiting an attacker-controlled webpage consisting of malicious POST data.
Solution / Fix
Apache Tomcat Error Message Reporting Cross Site Scripting Vulnerability
Solution:
The vendor released an update to address this issue. Please see the references for more information.
Apache Tomcat 3.3.2
Solution:
The vendor released an update to address this issue. Please see the references for more information.
Apache Tomcat 3.3.2
-
Apache Software Foundation CVE-2007-3384.patch
http://gulus.usherbrooke.ca/pub/appl/apache/tomcat/tomcat-3/v3.3.2-pat ches/src/CVE-2007-3384.patch
References
Apache Tomcat Error Message Reporting Cross Site Scripting Vulnerability
References:
References:
- Apache Tomcat 3.x vulnerabilities (Apache)
- Apache Tomcat Homepage (Apache)
- CVE-2007-3384: XSS in Tomcat cookies example (Apache)