Apache Tomcat Example Web Application Cross Site Scripting Vulnerability
BID:6720
Info
Apache Tomcat Example Web Application Cross Site Scripting Vulnerability
| Bugtraq ID: | 6720 |
| Class: | Input Validation Error |
| CVE: |
CVE-2003-0044 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 26 2003 12:00AM |
| Updated: | Jul 11 2009 08:06PM |
| Credit: | This vulnerability was reported by the Jakarta Tomcat Team. |
| Vulnerable: |
Apache Tomcat 3.3.1 a Apache Tomcat 3.3.1 Apache Tomcat 3.3 Apache Tomcat 3.2.4 Apache Tomcat 3.2.3 Apache Tomcat 3.2.1 Apache Tomcat 3.2 Apache Tomcat 3.1.1 Apache Tomcat 3.1 Apache Tomcat 3.0 |
| Not Vulnerable: |
Apache Tomcat 3.3.1 a |
Discussion
Apache Tomcat Example Web Application Cross Site Scripting Vulnerability
A vulnerability has been reported for Apache Tomcat. Reportedly, it is possible for an attacker to launch a cross site scripting attack.
The cross site scripting vulnerabilities exist in some sample web applications distributed with Apache Tomcat 3.3.1a and earlier.
This may enable a remote attacker to steal cookie-based authentication credentials from legitimate users of a host running Tomcat. Other attacks are also possible.
A vulnerability has been reported for Apache Tomcat. Reportedly, it is possible for an attacker to launch a cross site scripting attack.
The cross site scripting vulnerabilities exist in some sample web applications distributed with Apache Tomcat 3.3.1a and earlier.
This may enable a remote attacker to steal cookie-based authentication credentials from legitimate users of a host running Tomcat. Other attacks are also possible.
Exploit / POC
Apache Tomcat Example Web Application Cross Site Scripting Vulnerability
There is no exploit code required.
There is no exploit code required.
Solution / Fix
Apache Tomcat Example Web Application Cross Site Scripting Vulnerability
Solution:
HP has released an advisory (HPSBUX0303-249) that contains fixes to address this issue.
This issue will reportedly be addressed by the vendor in Tomcat version 3.3.2.
Fixes available:
Apache Tomcat 3.0
Apache Tomcat 3.1
Apache Tomcat 3.1.1
Apache Tomcat 3.2
Apache Tomcat 3.2.1
Apache Tomcat 3.2.3
Apache Tomcat 3.2.4
Apache Tomcat 3.3
Apache Tomcat 3.3.1
Solution:
HP has released an advisory (HPSBUX0303-249) that contains fixes to address this issue.
This issue will reportedly be addressed by the vendor in Tomcat version 3.3.2.
Fixes available:
Apache Tomcat 3.0
-
Apache Software Foundation Jakarta Tomcat 3.3.1a
http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/
Apache Tomcat 3.1
-
Apache Software Foundation Jakarta Tomcat 3.3.1a
http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/
Apache Tomcat 3.1.1
-
Apache Software Foundation Jakarta Tomcat 3.3.1a
http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/
Apache Tomcat 3.2
-
Apache Software Foundation Jakarta Tomcat 3.3.1a
http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/
Apache Tomcat 3.2.1
-
Apache Software Foundation Jakarta Tomcat 3.3.1a
http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/
Apache Tomcat 3.2.3
-
Apache Software Foundation Jakarta Tomcat 3.3.1a
http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/
Apache Tomcat 3.2.4
-
Apache Software Foundation Jakarta Tomcat 3.3.1a
http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/
Apache Tomcat 3.3
-
Apache Software Foundation Jakarta Tomcat 3.3.1a
http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/ -
Debian libapache-mod-jk_3.3a-4woody1_i386.deb
http://security.debian.org/pool/updates/contrib/t/tomcat/libapache-mod -jk_3.3a-4woody1_i386.deb -
Debian tomcat_3.3a-4woody1_all.deb
http://security.debian.org/pool/updates/contrib/t/tomcat/tomcat_3.3a-4 woody1_all.deb
Apache Tomcat 3.3.1
-
Apache Software Foundation Jakarta Tomcat 3.3.1a
http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/
References
Apache Tomcat Example Web Application Cross Site Scripting Vulnerability
References:
References:
- Apache Software Foundation Homepage (Apache Software Foundation)
- Tomcat Homepage (Apache Software Foundation)