CVE-2007-2450
Apache Tomcat <6.0.14 - XSS
Title source: llmDescription
Multiple cross-site scripting (XSS) vulnerabilities in the (1) Manager and (2) Host Manager web applications in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.36, 5.0.0 through 5.0.30, 5.5.0 through 5.5.24, and 6.0.0 through 6.0.13 allow remote authenticated users to inject arbitrary web script or HTML via a parameter name to manager/html/upload, and other unspecified vectors.
References (42)
... and 22 more
Scores
EPSS
0.0122
EPSS Percentile
78.9%
Classification
CWE
CWE-79
Status
draft
Affected Products (50)
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
... and 35 more
Timeline
Published
Jun 14, 2007
Tracked Since
Feb 18, 2026