CVE-2019-0221
MEDIUM NUCLEIApache Tomcat < 7.0.93 - XSS
Title source: ruleDescription
The SSI printenv command in Apache Tomcat 9.0.0.M1 to 9.0.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93 echoes user provided data without escaping and is, therefore, vulnerable to XSS. SSI is disabled by default. The printenv command is intended for debugging and is unlikely to be present in a production website.
Exploits (1)
exploitdb
WORKING POC
by Central InfoSec · textwebappsmultiple
https://www.exploit-db.com/exploits/50119
Nuclei Templates (1)
Apache Tomcat - Cross-Site Scripting
MEDIUMby pikpikcu
Shodan:
title:"Apache Tomcat" || http.title:"apache tomcat" || http.html:"apache tomcat" || cpe:"cpe:2.3:a:apache:tomcat"
FOFA:
body="apache tomcat" || title="apache tomcat"
References (29)
... and 9 more
Scores
CVSS v3
6.1
EPSS
0.1932
EPSS Percentile
95.4%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-79
Status
published
Products (3)
apache/tomcat
9.0.0 milestone1 (27 CPE variants)
apache/tomcat
7.0.0 - 7.0.93
org.apache.tomcat.embed/tomcat-embed-core
9.0.0 - 9.0.17Maven
Published
May 28, 2019
Tracked Since
Feb 18, 2026