[<prev] [next>] [day] [month] [year] [list]
Message-ID: <4670A764.8070608@apache.org>
Date: Wed, 13 Jun 2007 22:26:44 -0400
From: Mark Thomas <markt@...che.org>
To: Tomcat Users List <users@...cat.apache.org>,
Tomcat Developers List <dev@...cat.apache.org>,
full-disclosure@...ts.grok.org.uk, bugtraq@...urityfocus.com
Cc: JPCERT/CC Vulnerability Handling Team <vuls@...ert.or.jp>
Subject: [CVE-2007-2450]: Apache Tomcat XSS vulnerability in Manager
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
CVE-2007-2450: Apache Tomcat XSS vulnerabilities in Manager
Severity: low (cross-site scripting)
Vendor:
The Apache Software Foundation
Versions Affected:
Tomcat 4.0.0 to 4.0.6
Tomcat 4.1.0 to 4.1.36
Tomcat 5.0.0 to 5.0.30
Tomcat 5.5.0 to 5.5.24
Tomcat 6.0.0 to 6.0.13
Description:
The Manager and Host Manager web applications do not escape some user
provided data before including it in the output. This enables a XSS
attack. The user must be logged in to the Manager or Host Manager web
application.
Mitigation:
1. Log out of the Manager or Host Manager application (close the
browser) once tasks requiring use of the manager have been completed.
Example:
<form action="http://example.com:8080/manager/html/upload"
method="post" enctype="multipart/form-data">
<INPUT TYPE="hidden"
NAME='deployWar";filename="<script>alert()</script>"
Content-Type: image/gif' VALUE="abc">
<input type="submit">
</form>
Credit:
These issues were discovered by Daiki Fukumori, Secure Sky Technology.
References:
http://tomcat.apache.org/security.html
Mark Thomas
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.7 (MingW32)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org
iD8DBQFGcKdkb7IeiTPGAkMRAt1IAKCR47H3juKSvEdGwymOMCpKZdXi8wCgvrzl
aQy4/FihDqtrwRDLl0f/asA=
=RGcQ
-----END PGP SIGNATURE-----
Powered by blists - more mailing lists