Cross-site scripting in host-manager webapp (CVE-2008-1947)

Bug #270553 reported by Thierry Carrez
254
Affects Status Importance Assigned to Milestone
tomcat5.5 (Ubuntu)
Invalid
Low
Unassigned
Hardy
Fix Released
Low
Thierry Carrez

Bug Description

Binary package hint: tomcat5.5

Cross-site scripting (XSS) vulnerability in Apache Tomcat 5.5.9 through 5.5.26 and 6.0.0 through 6.0.16 allows remote attackers to inject arbitrary web script or HTML via the name parameter (aka the hostname attribute) to host-manager/html/add.

Revision history for this message
Thierry Carrez (ttx) wrote :

Fixed in intrepid (as of 5.5.26-3)

Changed in tomcat5.5:
importance: Undecided → Low
status: New → Invalid
Thierry Carrez (ttx)
Changed in tomcat5.5:
assignee: nobody → tcarrez
importance: Undecided → Low
status: New → In Progress
Revision history for this message
Thierry Carrez (ttx) wrote :

Proposed security fix for hardy

Changed in tomcat5.5:
status: In Progress → Fix Committed
Changed in tomcat5.5:
status: Fix Committed → Fix Released
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.