CVE-2011-0013

Apache Tomcat <5.5.32-7.0.6 - XSS

Title source: llm

Description

Multiple cross-site scripting (XSS) vulnerabilities in the HTML Manager Interface in Apache Tomcat 5.5 before 5.5.32, 6.0 before 6.0.30, and 7.0 before 7.0.6 allow remote attackers to inject arbitrary web script or HTML, as demonstrated via the display-name tag.

References (33)

... and 13 more

Scores

EPSS 0.2579
EPSS Percentile 96.2%

Classification

CWE
CWE-79
Status published

Affected Products (50)

apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
... and 35 more

Timeline

Published Feb 19, 2011
Tracked Since Feb 18, 2026