First published: Sat Dec 31 2005(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in the example web applications for Jakarta Tomcat 5.5.6 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) el/functions.jsp, (2) el/implicit-objects.jsp, and (3) jspx/textRotate.jspx in examples/jsp2/, as demonstrated via script in a request to snp/snoop.jsp. NOTE: other XSS issues in the manager were simultaneously reported, but these require admin access and do not cross privilege boundaries.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Tomcat | <=5.5.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-4838 is classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
CVE-2005-4838 affects Apache Tomcat versions 5.5.6 and earlier.
To fix CVE-2005-4838, upgrade your Apache Tomcat installation to version 5.5.7 or later.
CVE-2005-4838 represents multiple cross-site scripting (XSS) vulnerabilities in example web applications.
CVE-2005-4838 does not directly allow remote code execution but enables attackers to inject and execute arbitrary web scripts.