accept no compromises
Showing 1 - 1 of 1 RSS Feed

Files

Apache Tomcat Cross Site Scripting
Posted Mar 6, 2009
Authored by Deniz Cevik | Site tomcat.apache.org

The calendar application for Apache Tomcat contains invalid HTML which renders the cross site scripting protection for the time parameter ineffective. An attacker can therefore perform an cross site scripting attack using the time attribute. Version affected include Tomcat 6.0.0 to 6.0.18, Tomcat 5.5.0 to 5.5.27, and Tomcat 4.1.0 to 4.1.39.

tags | exploit, xss
advisories | CVE-2009-0781
MD5 | 4e4b4059d442851979d1c803c67cdf2f
Page 1 of 1
Back1Next

Top Authors In Last 30 Days

packet storm

© 2012 Packet Storm. All rights reserved.

close