First published: Wed May 14 2008(Updated: )
Cross-site scripting (XSS) vulnerability in Apache Tomcat 5.5.9 through 5.5.26 and 6.0.0 through 6.0.16 allows remote attackers to inject arbitrary web script or HTML via the name parameter (aka the hostname attribute) to `host-manager/html/add`.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/tomcat5 | <0:5.5.23-0jpp.7.el5_2.1 | 0:5.5.23-0jpp.7.el5_2.1 |
maven/org.apache.tomcat.embed:tomcat-embed-core | >=6.0.0<=6.0.16 | 6.0.18 |
maven/org.apache.tomcat.embed:tomcat-embed-core | >=5.5.9<=5.5.26 | 5.5.27 |
maven/org.apache.tomcat:tomcat | >=6.0.0<=6.0.16 | 6.0.18 |
maven/org.apache.tomcat:tomcat | >=5.5.9<=5.5.26 | 5.5.27 |
Tomcat | =5.5.9 | |
Tomcat | =5.5.10 | |
Tomcat | =5.5.11 | |
Tomcat | =5.5.12 | |
Tomcat | =5.5.13 | |
Tomcat | =5.5.14 | |
Tomcat | =5.5.15 | |
Tomcat | =5.5.16 | |
Tomcat | =5.5.17 | |
Tomcat | =5.5.18 | |
Tomcat | =5.5.19 | |
Tomcat | =5.5.20 | |
Tomcat | =5.5.21 | |
Tomcat | =5.5.22 | |
Tomcat | =5.5.23 | |
Tomcat | =5.5.24 | |
Tomcat | =5.5.25 | |
Tomcat | =5.5.26 | |
Tomcat | =6.0.0 | |
Tomcat | =6.0.1 | |
Tomcat | =6.0.2 | |
Tomcat | =6.0.3 | |
Tomcat | =6.0.4 | |
Tomcat | =6.0.5 | |
Tomcat | =6.0.6 | |
Tomcat | =6.0.7 | |
Tomcat | =6.0.8 | |
Tomcat | =6.0.9 | |
Tomcat | =6.0.10 | |
Tomcat | =6.0.11 | |
Tomcat | =6.0.12 | |
Tomcat | =6.0.13 | |
Tomcat | =6.0.14 | |
Tomcat | =6.0.15 | |
Tomcat | =6.0.16 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
CVE-2008-1947 is classified as a medium severity cross-site scripting vulnerability in Apache Tomcat.
To mitigate CVE-2008-1947, upgrade Apache Tomcat to version 5.5.27 or 6.0.18 or later.
CVE-2008-1947 affects Apache Tomcat versions from 5.5.9 to 5.5.26 and 6.0.0 to 6.0.16.
CVE-2008-1947 is a cross-site scripting (XSS) vulnerability allowing attackers to inject arbitrary web scripts.
CVE-2008-1947 can be exploited via the name parameter in the host-manager application.