Multiple cross-site scripting (XSS) vulnerabilities in the HTML Manager Interface in Apache Tomcat 5.5 before 5.5.32, 6.0 before 6.0.30, and 7.0 before 7.0.6 allow remote attackers to inject arbitrary web script or HTML, as demonstrated via the display-name tag.
References
Link Providers
http://lists.apple.com/archives/Security-announce/2011//Oct/msg00003.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2011-04/msg00000.html cve-icon cve-icon
http://marc.info/?l=bugtraq&m=130168502603566&w=2 cve-icon cve-icon
http://marc.info/?l=bugtraq&m=132215163318824&w=2 cve-icon cve-icon
http://marc.info/?l=bugtraq&m=136485229118404&w=2 cve-icon cve-icon
http://marc.info/?l=bugtraq&m=139344343412337&w=2 cve-icon cve-icon
http://secunia.com/advisories/43192 cve-icon cve-icon
http://secunia.com/advisories/45022 cve-icon cve-icon
http://secunia.com/advisories/57126 cve-icon cve-icon
http://securityreason.com/securityalert/8093 cve-icon cve-icon
http://support.apple.com/kb/HT5002 cve-icon cve-icon
http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5098550.html cve-icon cve-icon
http://tomcat.apache.org/security-5.html#Fixed_in_Apache_Tomcat_5.5.32 cve-icon cve-icon
http://tomcat.apache.org/security-6.html#Fixed_in_Apache_Tomcat_6.0.30 cve-icon cve-icon
http://tomcat.apache.org/security-7.html#Fixed_in_Apache_Tomcat_7.0.6_%28released_14_Jan_2011%29 cve-icon cve-icon
http://www.debian.org/security/2011/dsa-2160 cve-icon cve-icon
http://www.mandriva.com/security/advisories?name=MDVSA-2011:030 cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2011-0791.html cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2011-0896.html cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2011-0897.html cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2011-1845.html cve-icon cve-icon
http://www.securityfocus.com/archive/1/516209/30/90/threaded cve-icon cve-icon
http://www.securityfocus.com/bid/46174 cve-icon cve-icon
http://www.securitytracker.com/id?1025026 cve-icon cve-icon
http://www.vupen.com/english/advisories/2011/0376 cve-icon cve-icon
https://bugzilla.redhat.com/show_bug.cgi?id=675786 cve-icon cve-icon
https://lists.apache.org/thread.html/06cfb634bc7bf37af7d8f760f118018746ad8efbd519c4b789ac9c2e%40%3Cdev.tomcat.apache.org%3E cve-icon cve-icon
https://lists.apache.org/thread.html/8dcaf7c3894d66cb717646ea1504ea6e300021c85bb4e677dc16b1aa%40%3Cdev.tomcat.apache.org%3E cve-icon cve-icon
https://lists.apache.org/thread.html/r3aacc40356defc3f248aa504b1e48e819dd0471a0a83349080c6bcbf%40%3Cdev.tomcat.apache.org%3E cve-icon cve-icon
https://lists.apache.org/thread.html/r584a714f141eff7b1c358d4679288177bd4ca4558e9999d15867d4b5%40%3Cdev.tomcat.apache.org%3E cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2011-0013 cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12878 cve-icon cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14945 cve-icon cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19269 cve-icon cve-icon
https://www.cve.org/CVERecord?id=CVE-2011-0013 cve-icon
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2011-02-18T23:00:00

Updated: 2024-08-06T21:36:02.212Z

Reserved: 2010-12-07T00:00:00

Link: CVE-2011-0013

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2011-02-19T01:00:01.557

Modified: 2024-11-21T01:23:07.330

Link: CVE-2011-0013

cve-icon Redhat

Severity : Moderate

Publid Date: 2011-01-11T00:00:00Z

Links: CVE-2011-0013 - Bugzilla