CVE-2007-3382
Apache Tomcat Session ID Exposure via Cookie Delimiter Mishandling
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-3382. PoCs published by Tomasz Kuczynski.
AI-analyzed exploit summary This exploit demonstrates an information disclosure vulnerability in Apache Tomcat by manipulating cookie values to inject arbitrary data. The vulnerability arises from inadequate sanitization of user-supplied input in the CookieExample servlet.
Description
Apache Tomcat 6.0.0 to 6.0.13, 5.5.0 to 5.5.24, 5.0.0 to 5.0.30, 4.1.0 to 4.1.36, and 3.3 to 3.3.2 treats single quotes ("'") as delimiters in cookies, which might cause sensitive information such as session IDs to be leaked and allow remote attackers to conduct session hijacking attacks.
Exploits (1)
This exploit demonstrates an information disclosure vulnerability in Apache Tomcat by manipulating cookie values to inject arbitrary data. The vulnerability arises from inadequate sanitization of user-supplied input in the CookieExample servlet.