Cross-site scripting (XSS) vulnerability in jsp/cal/cal2.jsp in the calendar application in the examples web application in Apache Tomcat on Red Hat Enterprise Linux 5, Desktop Workstation 5, and Linux Desktop 5 allows remote attackers to inject arbitrary web script or HTML via the time parameter, related to "invalid HTML." NOTE: this is due to a missing fix for CVE-2009-0781.
CVSS Details
- CVSS 3.1 Base Score: 4.7
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade tomcat5-servlet-2.4-api-javadocUpgrade tomcat5-jsp-2.0-api-javadocUpgrade tomcat5Upgrade tomcat5-jsp-2.0-apiUpgrade tomcat5-common-libUpgrade tomcat5-servlet-2.4-apiUpgrade tomcat5-jasperUpgrade tomcat5-admin-webappsUpgrade tomcat5-webappsUpgrade tomcat5-server-libUpgrade tomcat5-jasper-javadoc | Dec 1, 2016 | Aug 5, 2010 |
| Oracle_linux | — | Upgrade tomcat5-jsp-2.0-api-javadocUpgrade tomcat5-servlet-2.4-api-javadocUpgrade tomcat5-jasper-javadocUpgrade tomcat5-admin-webappsUpgrade tomcat5Upgrade tomcat5-server-libUpgrade tomcat5-webappsUpgrade tomcat5-jsp-2.0-apiUpgrade tomcat5-jasperUpgrade tomcat5-servlet-2.4-apiUpgrade tomcat5-common-lib | Oct 16, 2024 | Aug 5, 2010 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub