VDB
CVE-2005-4838
CVE-2005-4838
PUBLISHED
Reported by redhat · Published April 25, 2007
Multiple cross-site scripting (XSS) vulnerabilities in the example web applications for Jakarta Tomcat 5.5.6 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) el/functions.jsp, (2) el/implicit-objects.jsp, and (3) jspx/textRotate.jspx in examples/jsp2/, as demonstrated via script in a request to snp/snoop.jsp. NOTE: other XSS issues in the manager were simultaneously reported, but these require admin access and do not cross privilege boundaries.
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| n/a | n/a | n/a, *, n/a |
Timeline
- Dec 31, 2005 CVE Published
- Feb 4, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Feb 3, 2023 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Jun 7, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
- Oct 30, 2023 EPSS Score
References
- x_refsource_CONFIRM
- tomcat-functions-xss(36467) vdb-entryx_refsource_XF
- 20070906 Apache Tomcat remote xss mailing-listx_refsource_FULLDISC
- RHSA-2008:0630 vendor-advisoryx_refsource_REDHAT
- 34878 vdb-entryx_refsource_OSVDB
- 12721 vdb-entryx_refsource_OSVDB
- 31493 third-party-advisoryx_refsource_SECUNIA
- [tomcat-dev] 20050103 [PATCH jakarta-servletapi-5] Re: Fwd: XSS in Jakarta Tomcat 5.5.6 mailing-listx_refsource_MLIST
- 34879 vdb-entryx_refsource_OSVDB
- 1012793 vdb-entryx_refsource_SECTRACK
- 13737 third-party-advisoryx_refsource_SECUNIA
- x_refsource_MISC
- x_refsource_CONFIRM
- RHSA-2008:0261 vendor-advisoryx_refsource_REDHAT
- [tomcat-dev] 20050103 Re: Fwd: XSS in Jakarta Tomcat 5.5.6 mailing-listx_refsource_MLIST
- [tomcat-dev] 20190319 svn commit: r1855831 [21/30] - in /tomcat/site/trunk: ./ docs/ xdocs/ mailing-listx_refsource_MLIST
- [tomcat-dev] 20190325 svn commit: r1856174 [19/29] - in /tomcat/site/trunk: docs/ xdocs/ xdocs/stylesheets/ mailing-listx_refsource_MLIST
- [tomcat-dev] 20200213 svn commit: r1873980 [24/34] - /tomcat/site/trunk/docs/ mailing-listx_refsource_MLIST