Apache Tomcat Cal2.JSP 跨站脚本攻击漏洞

漏洞信息详情

Apache Tomcat Cal2.JSP 跨站脚本攻击漏洞

漏洞简介

Apache Tomcat 4.1.31版本的日历范例应用程序中的cal2.jsp中存在跨站请求伪造漏洞。远程攻击者可以借助time和description参数像任意用户一样添加事件。

漏洞公告

目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:

Apache Software Foundation Tomcat 4.1

Apache Software Foundation v4.1.32

http://archive.apache.org/dist/tomcat/tomcat-4/v4.1.32/

Apache Software Foundation Tomcat 4.1.12

Apache Software Foundation v4.1.32

http://archive.apache.org/dist/tomcat/tomcat-4/v4.1.32/

Apache Software Foundation Tomcat 4.1.3 beta

Apache Software Foundation v4.1.32

http://archive.apache.org/dist/tomcat/tomcat-4/v4.1.32/

Apache Software Foundation Tomcat 4.1.31

Apache Software Foundation v4.1.32

http://archive.apache.org/dist/tomcat/tomcat-4/v4.1.32/

Apache Software Foundation Tomcat 5.5

Apache Software Foundation v5.5.16

http://archive.apache.org/dist/tomcat/tomcat-5/v5.5.16/

Apache Software Foundation Tomcat 5.5.1

Apache Software Foundation v5.5.16

http://archive.apache.org/dist/tomcat/tomcat-5/v5.5.16/

Apache Software Foundation Tomcat 5.5.10

Apache Software Foundation v5.5.16

http://archive.apache.org/dist/tomcat/tomcat-5/v5.5.16/

Apache Software Foundation Tomcat 5.5.11

Apache Software Foundation v5.5.16

http://archive.apache.org/dist/tomcat/tomcat-5/v5.5.16/

Apache Software Foundation Tomcat 5.5.12

Apache Software Foundation v5.5.16

http://archive.apache.org/dist/tomcat/tomcat-5/v5.5.16/

Apache Software Foundation Tomcat 5.5.13

Apache Software Foundation v5.5.16

http://archive.apache.org/dist/tomcat/tomcat-5/v5.5.16/

Apache Software Foundation Tomcat 5.5.14

Apache Software Foundation v5.5.16

http://archive.apache.org/dist/tomcat/tomcat-5/v5.5.16/

参考网址

来源: BUGTRAQ

名称: 20070904 Apache tomcat calendar example cross site scripting and cross site request forgery vulnerability

链接:http://www.securityfocus.com/archive/1/archive/1/478491/100/0/threaded

来源: OSVDB

名称: 41029

链接:http://osvdb.org/41029

来源: BUGTRAQ

名称: 20070904 Re: Apache tomcat calendar example cross site scripting and cross site request forgery vulnerability

链接:http://archives.neohapsis.com/archives/bugtraq/2007-09/0040.html

来源: SREASON

名称: 3094

链接:http://securityreason.com/securityalert/3094

受影响实体

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享