CVE-2007-1355

Tomcat 4.0.0-4.0.6, 4.1.0-4.1.36, 5.0.0-5.0.30, 5.5.0-5.5.23, 6.0.0-6.0.10 - Cross-Site Scripting

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2007-1355. PoCs published by Ferruh Mavituna.

AI-analyzed exploit summary This is a writeup describing a cross-site scripting (XSS) vulnerability in Apache Tomcat's documentation web application. It includes a proof-of-concept URL demonstrating the vulnerability but does not contain executable exploit code.

Description

Multiple cross-site scripting (XSS) vulnerabilities in the appdev/sample/web/hello.jsp example application in Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.36, 5.0.0 through 5.0.30, 5.5.0 through 5.5.23, and 6.0.0 through 6.0.10 allow remote attackers to inject arbitrary web script or HTML via the test parameter and unspecified vectors.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Ferruh Mavituna · textremotemultiple
https://www.exploit-db.com/exploits/30052

This is a writeup describing a cross-site scripting (XSS) vulnerability in Apache Tomcat's documentation web application. It includes a proof-of-concept URL demonstrating the vulnerability but does not contain executable exploit code.

Classification
Writeup 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: Apache Tomcat 4.0.0 to 4.0.6, 4.1.0 to 4.1.36, 5.0.0 to 5.0.30, 5.5.0 to 5.5.23, 6.0.0 to 6.0.10
No auth needed
Prerequisites: Access to the vulnerable Tomcat documentation web application
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (34)

Core 34
Core References
Various Sources x_refsource_confirm
http://tomcat.apache.org/security-4.html
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/30908
Vendor Advisory x_refsource_confirm
http://support.apple.com/kb/HT2163
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2008-0630.html
Vendor Advisory vendor-advisory x_refsource_sunalert
http://sunsolve.sun.com/search/document.do?assetkey=1-26-239312-1
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6111
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/1981/references
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/30899
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/31493
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/1979/references
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/34875
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/500412/100/0/threaded
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/33668
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/500396/100/0/threaded
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/2722
Mailing List vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2008//Jun/msg00002.html
Exploit, Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/24058
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2009/0233
Various Sources x_refsource_confirm
http://tomcat.apache.org/security-6.html
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2007/3386
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/30802
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/27037
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/27727
Various Sources x_refsource_confirm
http://tomcat.apache.org/security-5.html
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/469067/100/0/threaded
Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2008-0261.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/34377

Scores

EPSS 0.8245
EPSS Percentile 99.3%

Details

Status published
Products (50)
apache/tomcat 4.0.0
apache/tomcat 4.0.1
apache/tomcat 4.0.2
apache/tomcat 4.0.3
apache/tomcat 4.0.4
apache/tomcat 4.0.5
apache/tomcat 4.0.6
apache/tomcat 4.1.10
apache/tomcat 4.1.15
apache/tomcat 4.1.24
... and 40 more
Published May 21, 2007
Tracked Since Feb 18, 2026