CVE-2007-1358: XSS
Cross-site scripting (XSS) vulnerability in certain applications using Apache Tomcat 4.0.0 through 4.0.6 and 4.1.0 through 4.1.34 allows remote attackers to inject arbitrary web script or HTML via crafted "Accept-Language headers that do not conform to RFC 2616".
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-1358?
CVE-2007-1358 is considered to have a medium severity due to its cross-site scripting (XSS) capability.
How do I fix CVE-2007-1358?
To fix CVE-2007-1358, upgrade to Apache Tomcat version 4.1.35 or later, or implement input validation on Accept-Language headers.
Who is affected by CVE-2007-1358?
CVE-2007-1358 affects applications using Apache Tomcat versions 4.0.0 through 4.1.34.
What types of attacks can CVE-2007-1358 facilitate?
CVE-2007-1358 can facilitate attacks such as arbitrary web script or HTML injection through crafted headers.
What applications are most at risk from CVE-2007-1358?
Applications utilizing older versions of Apache Tomcat, specifically 4.0.x and 4.1.x versions, are most at risk from CVE-2007-1358.