CVE-2008-2370 Description Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16, when a RequestDispatcher is used, performs path normalization before removing the query string from the URI, which allows remote attackers to conduct directory traversal attacks and read arbitrary files via a .. (dot dot) in a request parameter. Related links: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-2370 https://mail-archives.apache.org/mod_mbox/tomcat-users/200808.mbox/%3C48931869.8070408@apache.org%3E Project Category n/a Tags data operational Date Disclosed 2008-08-04 Date Discovered 2008-05-21 JTVCYnJhbmNoX2xpc3QlNUQlNUIlMkZicmFuY2hfbGlzdCU1RA== Feel Vulnerable? Contact us so we can help you.
Read More
CVE-2008-1947 Description Cross-site scripting (XSS) vulnerability in Apache Tomcat 5.5.9 through 5.5.26 and 6.0.0 through 6.0.16 allows remote attackers to inject arbitrary web script or HTML via the name parameter (aka the hostname attribute) to host-manager/html/add. Related links: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-1947 https://mail-archives.apache.org/mod_mbox/tomcat-users/200806.mbox/%3C48446A11.7030702@apache.org%3E Project Category n/a Tags operational configuration Date Disclosed 2008-06-04 Date Discovered 2008-04-24 JTVCYnJhbmNoX2xpc3QlNUQlNUIlMkZicmFuY2hfbGlzdCU1RA== Feel Vulnerable? Contact us so we can help you.
Read More
CVE-2008-1232 Description Cross-site scripting (XSS) vulnerability in Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16 allows remote attackers to inject arbitrary web script or HTML via a crafted string that is used in the message argument to the HttpServletResponse.sendError method. Mitigation We recommend upgrading to a version of this component that is not vulnerable to this specific issue. Related links: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-1232 http://www.securityfocus.com/archive/1/archive/1/495021/100/0/threaded Project Category n/a Tags data operational Date Disclosed 2008-08-04 Date Discovered 2008-03-10 JTVCYnJhbmNoX2xpc3QlNUQlNUIlMkZicmFuY2hfbGlzdCU1RA== Feel Vulnerable? Contact us so we can help you.
Read More