Cross-site scripting (XSS) vulnerability in the calendar application example in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.31, 5.0.0 through 5.0.30, and 5.5.0 through 5.5.15 allows remote attackers to inject arbitrary web script or HTML via the time parameter to cal2.jsp and possibly unspecified other vectors. NOTE: this may be related to CVE-2006-0254.1.
CVSS Details
- CVSS 3.1 Base Score: 6.1
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apache Tomcat | — | Upgrade Apache Tomcat to 4.1.32Upgrade Apache Tomcat to 5.0.0Upgrade Apache Tomcat to 5.5.16Upgrade Apache Tomcat to the latest available version | May 17, 2012 | May 9, 2007 |
| Suse | — | Upgrade tomcat5-admin-webappsUpgrade apache2-mod_jkUpgrade suse-releaseUpgrade tomcat5Upgrade tomcat5-webapps | Feb 17, 2015 | May 9, 2007 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub