Apache Tomcat跨站脚本漏洞

漏洞信息详情

Apache Tomcat跨站脚本漏洞

漏洞简介

Apache Tomcat 3.2.1版本存在跨站脚本漏洞。恶意网络管理员在.JSP文件请求中嵌入Javascript,该漏洞导致Javascript插入到出错消息中。

漏洞公告

It has been suggested that this issue is rectified in versions 4.0-beta-2 and 3.2.2-beta-5 of Tomcat, although this has not been directly confirmed by the vendor.

参考网址

来源: BID
名称: 2982
链接:http://www.securityfocus.com/bid/2982

来源: jakarta.apache.org
链接:http://jakarta.apache.org/tomcat/tomcat-3.2-doc/readme

来源: BUGTRAQ
名称: 20010702 Multiple Vendor Java Servlet Container Cross-Site Scripting Vulnerability
链接:http://archive.cert.uni-stuttgart.de/archive/bugtraq/2001/07/msg00021.html

受影响实体

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享