Cross-site scripting (XSS) vulnerability in the Host Manager Servlet for Apache Tomcat 6.0.0 to 6.0.13 and 5.5.0 to 5.5.24 allows remote attackers to inject arbitrary HTML and web script via crafted requests, as demonstrated using the aliases parameter to an html/add action.
References
Link Providers
http://community.ca.com/blogs/casecurityresponseblog/archive/2009/01/23.aspx cve-icon cve-icon
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01178795 cve-icon cve-icon
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01192554 cve-icon cve-icon
http://jvn.jp/jp/JVN%2359851336/index.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00002.html cve-icon cve-icon
http://osvdb.org/36417 cve-icon cve-icon
http://secunia.com/advisories/26465 cve-icon cve-icon
http://secunia.com/advisories/26898 cve-icon cve-icon
http://secunia.com/advisories/27037 cve-icon cve-icon
http://secunia.com/advisories/27267 cve-icon cve-icon
http://secunia.com/advisories/27727 cve-icon cve-icon
http://secunia.com/advisories/28317 cve-icon cve-icon
http://secunia.com/advisories/33668 cve-icon cve-icon
http://securityreason.com/securityalert/3010 cve-icon cve-icon
http://securitytracker.com/id?1018558 cve-icon cve-icon
http://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=197540 cve-icon cve-icon
http://tomcat.apache.org/security-6.html cve-icon cve-icon
http://www.debian.org/security/2008/dsa-1447 cve-icon cve-icon
http://www.mandriva.com/security/advisories?name=MDKSA-2007:241 cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2007-0871.html cve-icon cve-icon
http://www.securityfocus.com/archive/1/476448/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/500396/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/500412/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/bid/25314 cve-icon cve-icon
http://www.vupen.com/english/advisories/2007/2880 cve-icon cve-icon
http://www.vupen.com/english/advisories/2007/3386 cve-icon cve-icon
http://www.vupen.com/english/advisories/2007/3527 cve-icon cve-icon
http://www.vupen.com/english/advisories/2009/0233 cve-icon cve-icon
https://exchange.xforce.ibmcloud.com/vulnerabilities/36001 cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2007-3386 cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10077 cve-icon cve-icon
https://www.cve.org/CVERecord?id=CVE-2007-3386 cve-icon
https://www.redhat.com/archives/fedora-package-announce/2007-November/msg00525.html cve-icon cve-icon
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2007-08-14T22:00:00

Updated: 2024-08-07T14:14:13.015Z

Reserved: 2007-06-25T00:00:00

Link: CVE-2007-3386

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2007-08-14T22:17:00.000

Modified: 2024-11-21T00:33:06.730

Link: CVE-2007-3386

cve-icon Redhat

Severity : Low

Publid Date: 2007-08-14T00:00:00Z

Links: CVE-2007-3386 - Bugzilla