CVE-2013-6357

Apache Tomcat < 5.5.25 - Cross-Site Request Forgery via Manager Application

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2013-6357. PoCs published by Ivano Binetti.

AI-analyzed exploit summary This exploit demonstrates a CSRF vulnerability in Apache Tomcat 5.5.25 and below, allowing an attacker to undeploy applications via a crafted HTML form. The PoC automates the submission of a POST request to the Manager application's undeploy endpoint.

Description

Cross-site request forgery (CSRF) vulnerability in the Manager application in Apache Tomcat 5.5.25 and earlier allows remote attackers to hijack the authentication of administrators for requests that manipulate application deployment via the POST method, as demonstrated by a /manager/html/undeploy?path= URI. NOTE: the vendor disputes the significance of this report, stating that "the Apache Tomcat Security team has not accepted any reports of CSRF attacks against the Manager application ... as they require a reckless system administrator.

Exploits (1)

exploitdb WORKING POC
by Ivano Binetti · textwebappsmultiple
https://www.exploit-db.com/exploits/29435

This exploit demonstrates a CSRF vulnerability in Apache Tomcat 5.5.25 and below, allowing an attacker to undeploy applications via a crafted HTML form. The PoC automates the submission of a POST request to the Manager application's undeploy endpoint.

Classification
Working Poc 90%
Attack Type
Other
Complexity
Trivial
Reliability
Reliable
Target: Apache Tomcat 5.5.25 and below
Auth required
Prerequisites: Victim must be authenticated to the Tomcat Manager application · Victim must visit the malicious HTML page
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Scores

EPSS 0.0254
EPSS Percentile 82.9%

Details

CWE
CWE-352
Status published
Products (48)
apache/tomcat 1.1.3
apache/tomcat 3.0
apache/tomcat 3.1
apache/tomcat 3.1.1
apache/tomcat 3.2
apache/tomcat 3.2.1
apache/tomcat 3.2.2 (2 CPE variants)
apache/tomcat 3.2.3
apache/tomcat 3.2.4
apache/tomcat 3.3
... and 38 more
Published Nov 13, 2013
Tracked Since Feb 18, 2026