Apache Tomcat Cross-Site Scripting Vulnerability
Publish Date: 21 juillet 2015
Gravité: : Medium
Identifiant(s) CVE: : CVE-2006-7195
Date du conseil: 21 juillet 2015
Description
Cross-site scripting (XSS) vulnerability in implicit-objects.jsp in Apache Tomcat 5.0.0 through 5.0.30 and 5.5.0 through 5.5.17 allows remote attackers to inject arbitrary web script or HTML via certain header values.
Information Exposure Rating:
Apply associated Trend Micro DPI Rules.
Solutions
Trend Micro Deep Security DPI Rule Number: 1000552
Trend Micro Deep Security DPI Rule Name: 1000552 - Generic Cross Site Scripting(XSS) Prevention
Affected software and version:
- Apache Tomcat 5.0.0
- Apache Tomcat 5.0.1
- Apache Tomcat 5.0.10
- Apache Tomcat 5.0.11
- Apache Tomcat 5.0.12
- Apache Tomcat 5.0.13
- Apache Tomcat 5.0.14
- Apache Tomcat 5.0.15
- Apache Tomcat 5.0.16
- Apache Tomcat 5.0.17
- Apache Tomcat 5.0.18
- Apache Tomcat 5.0.19
- Apache Tomcat 5.0.2
- Apache Tomcat 5.0.21
- Apache Tomcat 5.0.22
- Apache Tomcat 5.0.23
- Apache Tomcat 5.0.24
- Apache Tomcat 5.0.25
- Apache Tomcat 5.0.26
- Apache Tomcat 5.0.27
- Apache Tomcat 5.0.28
- Apache Tomcat 5.0.29
- Apache Tomcat 5.0.30
- Apache Tomcat 5.5.0
- Apache Tomcat 5.5.10
- Apache Tomcat 5.5.11
- Apache Tomcat 5.5.12
- Apache Tomcat 5.5.13
- Apache Tomcat 5.5.14
- Apache Tomcat 5.5.15
- Apache Tomcat 5.5.16
- Apache Tomcat 5.5.17
- Apache Tomcat 5.5.5
- Apache Tomcat 5.5.6
- Apache Tomcat 5.5.7
- Apache Tomcat 5.5.8
- Apache Tomcat 5.5.9