20101122 [SECURITY] CVE-2010-4172: Apache Tomcat Manager application XSS vulnerabilitymailing list
http://archives.neohapsis.com/archives/fulldisclosure/2010-11/0285.html CVE-2010-4172
Improper Neutralization of Input During Web Page Generation in Apache Tomcat
Record summary
CVE-2010-4172 has a selected CVSS score of 4.3; EIP currently links 1 catalogued exploit.
Description
Multiple cross-site scripting (XSS) vulnerabilities in the Manager application in Apache Tomcat 6.0.12 through 6.0.29 and 7.0.0 through 7.0.4 allow remote attackers to inject arbitrary web script or HTML via the (1) orderBy or (2) sort parameter to sessionsList.jsp, or unspecified input to (3) sessionDetail.jsp or (4) java/org/apache/catalina/manager/JspHelper.java, related to use of untrusted web applications.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
org.apache.tomcat:tomcatBrowse Maven / org.apache.tomcat:tomcat | GitHub Advisory | 7.0.0 to < 7.0.5 · Fixed in 7.0.5 | affected |
| 6.0.12 to ≤ 6.0.29 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBApache Tomcat 7.0.4 - 'sort' / 'orderBy' Cross-Site ScriptingExploitDB exploitby Adam MuntnerNot analyzed1 file
References
Showing 12 of 36APPLE-SA-2011-10-12-3Vendor advisory
http://lists.apple.com/archives/Security-announce/2011//Oct/msg00003.html HPSBST02955Vendor advisory
http://marc.info/?l=bugtraq&m=139344343412337&w=2 42337Third-party advisory
http://secunia.com/advisories/42337 43019Third-party advisory
http://secunia.com/advisories/43019 45022Third-party advisory
http://secunia.com/advisories/45022 57126Third-party advisory
http://secunia.com/advisories/57126 1024764vdb entry
http://securitytracker.com/id?1024764 support.apple.comConfirmation
http://support.apple.com/kb/HT5002 support.novell.comConfirmation
http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5098550.html svn.apache.orgConfirmation
http://svn.apache.org/viewvc?view=revision&revision=1037778 svn.apache.orgConfirmation
http://svn.apache.org/viewvc?view=revision&revision=1037779