Schweregrad: : Medium
  Identificador(es) CVE: : CVE-2007-1355
  Data do informe: 21 julho 2015

  Descrição

Multiple cross-site scripting (XSS) vulnerabilities in the appdev/sample/web/hello.jsp example application in Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.36, 5.0.0 through 5.0.30, 5.5.0 through 5.5.23, and 6.0.0 through 6.0.10 allow remote attackers to inject arbitrary web script or HTML via the test parameter and unspecified vectors.

  Exposição das informações

Apply associated Trend Micro DPI Rules.

  Solução

  Trend Micro Deep Security DPI Rule Number: 1000552
  Trend Micro Deep Security DPI Rule Name: 1000552 - Generic Cross Site Scripting(XSS) Prevention

  Software infectado e versão:

  • Apache Tomcat 4.0.0
  • Apache Tomcat 4.0.1
  • Apache Tomcat 4.0.2
  • Apache Tomcat 4.0.3
  • Apache Tomcat 4.0.4
  • Apache Tomcat 4.0.5
  • Apache Tomcat 4.0.6
  • Apache Tomcat 4.1.10
  • Apache Tomcat 4.1.15
  • Apache Tomcat 4.1.24
  • Apache Tomcat 4.1.28
  • Apache Tomcat 4.1.31
  • Apache Tomcat 5.0.1
  • Apache Tomcat 5.0.10
  • Apache Tomcat 5.0.11
  • Apache Tomcat 5.0.12
  • Apache Tomcat 5.0.13
  • Apache Tomcat 5.0.14
  • Apache Tomcat 5.0.15
  • Apache Tomcat 5.0.16
  • Apache Tomcat 5.0.17
  • Apache Tomcat 5.0.18
  • Apache Tomcat 5.0.19
  • Apache Tomcat 5.0.2
  • Apache Tomcat 5.0.21
  • Apache Tomcat 5.0.22
  • Apache Tomcat 5.0.23
  • Apache Tomcat 5.0.24
  • Apache Tomcat 5.0.25
  • Apache Tomcat 5.0.26
  • Apache Tomcat 5.0.27
  • Apache Tomcat 5.0.28
  • Apache Tomcat 5.0.29
  • Apache Tomcat 5.0.3
  • Apache Tomcat 5.0.30
  • Apache Tomcat 5.0.4
  • Apache Tomcat 5.0.5
  • Apache Tomcat 5.0.6
  • Apache Tomcat 5.0.7
  • Apache Tomcat 5.0.8
  • Apache Tomcat 5.0.9
  • Apache Tomcat 6.0.0
  • Apache Tomcat 6.0.1
  • Apache Tomcat 6.0.10
  • Apache Tomcat 6.0.2
  • Apache Tomcat 6.0.3
  • Apache Tomcat 6.0.4
  • Apache Tomcat 6.0.5
  • Apache Tomcat 6.0.6
  • Apache Tomcat 6.0.7
  • Apache Tomcat 6.0.8
  • Apache Tomcat 6.0.9