CVE-2010-4172
Apache Tomcat < 7.0.5 - XSS
Title source: ruleDescription
Multiple cross-site scripting (XSS) vulnerabilities in the Manager application in Apache Tomcat 6.0.12 through 6.0.29 and 7.0.0 through 7.0.4 allow remote attackers to inject arbitrary web script or HTML via the (1) orderBy or (2) sort parameter to sessionsList.jsp, or unspecified input to (3) sessionDetail.jsp or (4) java/org/apache/catalina/manager/JspHelper.java, related to use of untrusted web applications.
Exploits (1)
exploitdb
WRITEUP
VERIFIED
by Adam Muntner · textremotelinux
https://www.exploit-db.com/exploits/35011
References (24)
... and 4 more
Scores
EPSS
0.1190
EPSS Percentile
93.7%
Classification
CWE
CWE-79
Status
published
Affected Products (22)
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
... and 7 more
Timeline
Published
Nov 26, 2010
Tracked Since
Feb 18, 2026