Apache Tomcat跨站脚本漏洞

Apache Tomcat跨站脚本漏洞

漏洞ID 1106936 漏洞类型 其他
发布时间 2002-08-21 更新时间 2003-10-06
图片[1]-Apache Tomcat跨站脚本漏洞-安全小百科CVE编号 CVE-2002-1567
图片[2]-Apache Tomcat跨站脚本漏洞-安全小百科CNNVD-ID CNNVD-200310-009
漏洞平台 Unix CVSS评分 6.8
|漏洞来源
https://www.exploit-db.com/exploits/21734
https://www.securityfocus.com/bid/82870
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200310-009
|漏洞详情
Apache Tomcat 4.1版本存在跨站脚本(XSS)漏洞。远程攻击者借助带有编码换行符的URL执行任意web脚本和盗取cookies,该换行符后面接有名字包含脚本的.jsp文件请求。

|漏洞EXP
source: http://www.securityfocus.com/bid/5542/info

Jakarta Tomcat is a Java Servlet and JSP server produced by the Apache Software Foundation. Tomcat is available for Microsoft Windows, Linux, and other Unix based operating systems.

A cross site scripting vulnerability has been reported in some versions of Tomcat. Reportedly, if a HTTP request is made for a JSP, malicious script code embedded in the URI may be included in a page generated by Tomcat.

This may be related to the issues discussed in BID 2982. This has not, however, been confirmed.

http://example.com:8080/666%0a%0a<script>alert("asdf");</script>666.jsp
|受影响的产品
Apache Tomcat 4.1

BSDI BSD/OS 4.0

Caldera OpenLinux 2.4

Debian Linux 2.3

|参考资料

来源:VULN-DEV
名称:20020821ApacheTomcat4.1Cross-SiteScriptingVulnerability
链接:http://archives.neohapsis.com/archives/vuln-dev/2002-q3/0482.html
来源:tomcat.apache.org
链接:http://tomcat.apache.org/security-4.html

相关推荐: Nite Server FTPd Multiple DoS Vulnerabilities

Nite Server FTPd Multiple DoS Vulnerabilities 漏洞ID 1104218 漏洞类型 Boundary Condition Error 发布时间 2000-05-19 更新时间 2000-05-19 CVE编号 N/A…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享