CVE-2006-7195: XSS
According to http://tomcat.apache.org/security-5.html
Fixed in Apache Tomcat 5.5.18
Cross-site scripting CVE-2006-7195
The implict-objects.jsp in the examples webapp displayed a number of unfiltered header values. This enabled a XSS attack. These values are now filtered.
Affects: 5.0.0-5.0.HEAD, 5.5.0-5.5.17
Other sources
Cross-site scripting (XSS) vulnerability in implicit-objects.jsp in Apache Tomcat 5.0.0 through 5.0.30 and 5.5.0 through 5.5.17 allows remote attackers to inject arbitrary web script or HTML via certain header values.
— Red Hat
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2006-7195?
CVE-2006-7195 has been classified as a cross-site scripting vulnerability with a medium level of severity.
How do I fix CVE-2006-7195?
To fix CVE-2006-7195, upgrade Apache Tomcat to version 5.5.18 or later.
Which versions of Apache Tomcat are affected by CVE-2006-7195?
CVE-2006-7195 affects Apache Tomcat versions 5.0.0 to 5.0.30 and 5.5.0 to 5.5.17.
What types of attacks can CVE-2006-7195 allow?
CVE-2006-7195 can allow attackers to execute arbitrary scripts in a user's browser.
When was CVE-2006-7195 published?
CVE-2006-7195 was published on January 2, 2007.