Apache Tomcat Servlet Mapping Cross Site Scripting Vulnerability
BID:5193
Info
Apache Tomcat Servlet Mapping Cross Site Scripting Vulnerability
| Bugtraq ID: | 5193 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 10 2002 12:00AM |
| Updated: | Jul 10 2002 12:00AM |
| Credit: | Discovery credited to Matt Moore <[email protected]>. |
| Vulnerable: |
Apache Tomcat 4.0.3 |
| Not Vulnerable: | |
Discussion
Apache Tomcat Servlet Mapping Cross Site Scripting Vulnerability
A vulnerability has been reported for Apache Tomcat 4.0.3 on Microsoft Windows and Linux platforms. Reportedly, it is possible for an attacker to launch a cross site scripting attack.
When servlet mapping is enabled, it is possible to invoke various servlets and classes and cause Apache Tomcat to throw an exception. This will make cross site scripting attacks possible.
A vulnerability has been reported for Apache Tomcat 4.0.3 on Microsoft Windows and Linux platforms. Reportedly, it is possible for an attacker to launch a cross site scripting attack.
When servlet mapping is enabled, it is possible to invoke various servlets and classes and cause Apache Tomcat to throw an exception. This will make cross site scripting attacks possible.
Solution / Fix
Apache Tomcat Servlet Mapping Cross Site Scripting Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Apache Tomcat Servlet Mapping Cross Site Scripting Vulnerability
References:
References: