CVE-2007-3384 Information

Description

Multiple cross-site scripting (XSS) vulnerabilities in examples/servlet/CookieExample in Apache Tomcat 3.3 through 3.3.2 allow remote attackers to inject arbitrary web script or HTML via the (1) Name or (2) Value field related to error messages.

Reference

http://osvdb.org/39035 http://securityreason.com/securityalert/2971 http://securitytracker.com/id?1018503 http://tomcat.apache.org/security-3.html http://www.securityfocus.com/archive/1/475321/100/0/threaded http://www.securityfocus.com/bid/25174

Share on: