community.ca.comConfirmation
http://community.ca.com/blogs/casecurityresponseblog/archive/2009/01/23.aspx CVE-2007-3386
Apache Tomcat 6.0.13 - Host Manager Servlet Cross-Site Scripting
Record summary
CVE-2007-3386 has a selected CVSS score of 4.3; EIP currently links 1 catalogued exploit.
Description
Cross-site scripting (XSS) vulnerability in the Host Manager Servlet for Apache Tomcat 6.0.0 to 6.0.13 and 5.5.0 to 5.5.24 allows remote attackers to inject arbitrary HTML and web script via crafted requests, as demonstrated using the aliases parameter to an html/add action.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBApache Tomcat 6.0.13 - Host Manager Servlet Cross-Site ScriptingExploitDB exploitby NTT OSS CENTERNot analyzed1 file
References
Showing 12 of 32SSRT071447Vendor advisory
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01178795 SSRT071472Vendor advisory
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01192554 JVN#59851336Third-party advisory
http://jvn.jp/jp/JVN%2359851336/index.html SUSE-SR:2009:004Vendor advisory
http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00002.html 36417vdb entry
http://osvdb.org/36417 26465Third-party advisory
http://secunia.com/advisories/26465 26898Third-party advisory
http://secunia.com/advisories/26898 27037Third-party advisory
http://secunia.com/advisories/27037 27267Third-party advisory
http://secunia.com/advisories/27267 27727Third-party advisory
http://secunia.com/advisories/27727 28317Third-party advisory
http://secunia.com/advisories/28317