Cross-site scripting (XSS) vulnerability in Apache Tomcat 5.5.9 through 5.5.26 and 6.0.0 through 6.0.16 allows remote attackers to inject arbitrary web script or HTML via the name parameter (aka the hostname attribute) to host-manager/html/add.
Advisories
Source ID Title
Debian DSA Debian DSA DSA-1593-1 New tomcat5.5 packages cross-site scripting
Github GHSA Github GHSA GHSA-f98p-9pp6-7q6c Apache Tomcat Cross-site scripting (XSS) vulnerability
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

References
Link Providers
http://lists.apple.com/archives/security-announce/2008/Oct/msg00001.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2008-07/msg00001.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00002.html cve-icon cve-icon
http://marc.info/?l=bugtraq&m=123376588623823&w=2 cve-icon cve-icon
http://marc.info/?l=bugtraq&m=139344343412337&w=2 cve-icon cve-icon
http://marc.info/?l=tomcat-user&m=121244319501278&w=2 cve-icon cve-icon
http://secunia.com/advisories/30500 cve-icon cve-icon
http://secunia.com/advisories/30592 cve-icon cve-icon
http://secunia.com/advisories/30967 cve-icon cve-icon
http://secunia.com/advisories/31639 cve-icon cve-icon
http://secunia.com/advisories/31865 cve-icon cve-icon
http://secunia.com/advisories/31891 cve-icon cve-icon
http://secunia.com/advisories/32120 cve-icon cve-icon
http://secunia.com/advisories/32222 cve-icon cve-icon
http://secunia.com/advisories/32266 cve-icon cve-icon
http://secunia.com/advisories/33797 cve-icon cve-icon
http://secunia.com/advisories/33999 cve-icon cve-icon
http://secunia.com/advisories/34013 cve-icon cve-icon
http://secunia.com/advisories/37460 cve-icon cve-icon
http://secunia.com/advisories/57126 cve-icon cve-icon
http://support.apple.com/kb/HT3216 cve-icon cve-icon
http://support.avaya.com/elmodocs2/security/ASA-2008-401.htm cve-icon cve-icon
http://tomcat.apache.org/security-5.html cve-icon cve-icon
http://tomcat.apache.org/security-6.html cve-icon cve-icon
http://www.debian.org/security/2008/dsa-1593 cve-icon cve-icon
http://www.mandriva.com/security/advisories?name=MDVSA-2008:188 cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2008-0648.html cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2008-0862.html cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2008-0864.html cve-icon cve-icon
http://www.securityfocus.com/archive/1/492958/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/507985/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/bid/29502 cve-icon cve-icon
http://www.securityfocus.com/bid/31681 cve-icon cve-icon
http://www.securitytracker.com/id?1020624 cve-icon cve-icon
http://www.vmware.com/security/advisories/VMSA-2009-0002.html cve-icon cve-icon
http://www.vmware.com/security/advisories/VMSA-2009-0016.html cve-icon cve-icon
http://www.vupen.com/english/advisories/2008/1725 cve-icon cve-icon
http://www.vupen.com/english/advisories/2008/2780 cve-icon cve-icon
http://www.vupen.com/english/advisories/2008/2823 cve-icon cve-icon
http://www.vupen.com/english/advisories/2009/0320 cve-icon cve-icon
http://www.vupen.com/english/advisories/2009/0503 cve-icon cve-icon
http://www.vupen.com/english/advisories/2009/3316 cve-icon cve-icon
https://exchange.xforce.ibmcloud.com/vulnerabilities/42816 cve-icon cve-icon
https://lists.apache.org/thread.html/06cfb634bc7bf37af7d8f760f118018746ad8efbd519c4b789ac9c2e%40%3Cdev.tomcat.apache.org%3E cve-icon cve-icon
https://lists.apache.org/thread.html/8dcaf7c3894d66cb717646ea1504ea6e300021c85bb4e677dc16b1aa%40%3Cdev.tomcat.apache.org%3E cve-icon cve-icon
https://lists.apache.org/thread.html/r3aacc40356defc3f248aa504b1e48e819dd0471a0a83349080c6bcbf%40%3Cdev.tomcat.apache.org%3E cve-icon cve-icon
https://lists.apache.org/thread.html/r584a714f141eff7b1c358d4679288177bd4ca4558e9999d15867d4b5%40%3Cdev.tomcat.apache.org%3E cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2008-1947 cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11534 cve-icon cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6009 cve-icon cve-icon
https://www.cve.org/CVERecord?id=CVE-2008-1947 cve-icon
https://www.redhat.com/archives/fedora-package-announce/2008-September/msg00712.html cve-icon cve-icon
https://www.redhat.com/archives/fedora-package-announce/2008-September/msg00859.html cve-icon cve-icon
https://www.redhat.com/archives/fedora-package-announce/2008-September/msg00889.html cve-icon cve-icon
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2024-08-07T08:40:59.911Z

Reserved: 2008-04-24T00:00:00

Link: CVE-2008-1947

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2008-06-04T19:32:00.000

Modified: 2025-04-09T00:30:58.490

Link: CVE-2008-1947

cve-icon Redhat

Severity : Low

Publid Date: 2008-06-02T00:00:00Z

Links: CVE-2008-1947 - Bugzilla

cve-icon OpenCVE Enrichment

No data.