First published: Thu Nov 22 2001(Updated: )
A cross-site scripting vulnerability in Apache Tomcat 3.2.1 allows a malicious webmaster to embed Javascript in a request for a .JSP file, which causes the Javascript to be inserted into an error message.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
maven/org.apache.tomcat:tomcat | <=3.2.1 | |
Apache Tomcat | =3.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2001-0829 is classified as a medium severity vulnerability.
To fix CVE-2001-0829, upgrade Apache Tomcat to a version later than 3.2.1.
CVE-2001-0829 affects users running Apache Tomcat version 3.2.1.
CVE-2001-0829 enables a cross-site scripting attack that allows JavaScript injection through error messages.
CVE-2001-0829 is a security risk because it allows attackers to execute arbitrary JavaScript in the context of a user's session.