CVE-2006-7196
Cross-site scripting in Apache Tomcat
EPSS 72.2%
描述
Cross-site scripting (XSS) vulnerability in the calendar application example in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.31, 5.0.0 through 5.0.30, and 5.5.0 through 5.5.15 allows remote attackers to inject arbitrary web script or HTML via the time parameter to cal2.jsp and possibly unspecified other vectors. NOTE: this may be related to CVE-2006-0254.1.
如何修補 CVE-2006-7196
要修補 CVE-2006-7196,請將受影響套件升級到下列已修補版本。
- Maven/org.apache.tomcat:tomcat—升級至 4.0.7 或更新版本
CVE-2006-7196 正在被利用嗎?
可能 — EPSS 為 72.2%,屬於高被利用機率區間,建議優先修補。
受影響套件(1)
- >= 4.0.0, < 4.0.7