Cross-site scripting (XSS) vulnerability in Apache Tomcat 5.5.9 through 5.5.26 and 6.0.0 through 6.0.16 allows remote attackers to inject arbitrary web script or HTML via the name parameter (aka the hostname attribute) to host-manager/html/add.
References
Link Providers
http://lists.apple.com/archives/security-announce/2008/Oct/msg00001.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2008-07/msg00001.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00002.html cve-icon cve-icon
http://marc.info/?l=bugtraq&m=123376588623823&w=2 cve-icon cve-icon
http://marc.info/?l=bugtraq&m=139344343412337&w=2 cve-icon cve-icon
http://marc.info/?l=tomcat-user&m=121244319501278&w=2 cve-icon cve-icon
http://secunia.com/advisories/30500 cve-icon cve-icon
http://secunia.com/advisories/30592 cve-icon cve-icon
http://secunia.com/advisories/30967 cve-icon cve-icon
http://secunia.com/advisories/31639 cve-icon cve-icon
http://secunia.com/advisories/31865 cve-icon cve-icon
http://secunia.com/advisories/31891 cve-icon cve-icon
http://secunia.com/advisories/32120 cve-icon cve-icon
http://secunia.com/advisories/32222 cve-icon cve-icon
http://secunia.com/advisories/32266 cve-icon cve-icon
http://secunia.com/advisories/33797 cve-icon cve-icon
http://secunia.com/advisories/33999 cve-icon cve-icon
http://secunia.com/advisories/34013 cve-icon cve-icon
http://secunia.com/advisories/37460 cve-icon cve-icon
http://secunia.com/advisories/57126 cve-icon cve-icon
http://support.apple.com/kb/HT3216 cve-icon cve-icon
http://support.avaya.com/elmodocs2/security/ASA-2008-401.htm cve-icon cve-icon
http://tomcat.apache.org/security-5.html cve-icon cve-icon
http://tomcat.apache.org/security-6.html cve-icon cve-icon
http://www.debian.org/security/2008/dsa-1593 cve-icon cve-icon
http://www.mandriva.com/security/advisories?name=MDVSA-2008:188 cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2008-0648.html cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2008-0862.html cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2008-0864.html cve-icon cve-icon
http://www.securityfocus.com/archive/1/492958/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/507985/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/bid/29502 cve-icon cve-icon
http://www.securityfocus.com/bid/31681 cve-icon cve-icon
http://www.securitytracker.com/id?1020624 cve-icon cve-icon
http://www.vmware.com/security/advisories/VMSA-2009-0002.html cve-icon cve-icon
http://www.vmware.com/security/advisories/VMSA-2009-0016.html cve-icon cve-icon
http://www.vupen.com/english/advisories/2008/1725 cve-icon cve-icon
http://www.vupen.com/english/advisories/2008/2780 cve-icon cve-icon
http://www.vupen.com/english/advisories/2008/2823 cve-icon cve-icon
http://www.vupen.com/english/advisories/2009/0320 cve-icon cve-icon
http://www.vupen.com/english/advisories/2009/0503 cve-icon cve-icon
http://www.vupen.com/english/advisories/2009/3316 cve-icon cve-icon
https://exchange.xforce.ibmcloud.com/vulnerabilities/42816 cve-icon cve-icon
https://lists.apache.org/thread.html/06cfb634bc7bf37af7d8f760f118018746ad8efbd519c4b789ac9c2e%40%3Cdev.tomcat.apache.org%3E cve-icon cve-icon
https://lists.apache.org/thread.html/8dcaf7c3894d66cb717646ea1504ea6e300021c85bb4e677dc16b1aa%40%3Cdev.tomcat.apache.org%3E cve-icon cve-icon
https://lists.apache.org/thread.html/r3aacc40356defc3f248aa504b1e48e819dd0471a0a83349080c6bcbf%40%3Cdev.tomcat.apache.org%3E cve-icon cve-icon
https://lists.apache.org/thread.html/r584a714f141eff7b1c358d4679288177bd4ca4558e9999d15867d4b5%40%3Cdev.tomcat.apache.org%3E cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2008-1947 cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11534 cve-icon cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6009 cve-icon cve-icon
https://www.cve.org/CVERecord?id=CVE-2008-1947 cve-icon
https://www.redhat.com/archives/fedora-package-announce/2008-September/msg00712.html cve-icon cve-icon
https://www.redhat.com/archives/fedora-package-announce/2008-September/msg00859.html cve-icon cve-icon
https://www.redhat.com/archives/fedora-package-announce/2008-September/msg00889.html cve-icon cve-icon
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2008-06-04T19:17:00

Updated: 2024-08-07T08:40:59.911Z

Reserved: 2008-04-24T00:00:00

Link: CVE-2008-1947

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2008-06-04T19:32:00.000

Modified: 2024-11-21T00:45:43.850

Link: CVE-2008-1947

cve-icon Redhat

Severity : Low

Publid Date: 2008-06-02T00:00:00Z

Links: CVE-2008-1947 - Bugzilla