CVE-2007-2449
Apache Tomcat XSS Vulnerabilities in Examples Web Application
EPSS 77.4%
描述
Multiple cross-site scripting (XSS) vulnerabilities in certain JSP files in the examples web application in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.36, 5.0.0 through 5.0.30, 5.5.0 through 5.5.24, and 6.0.0 through 6.0.13 allow remote attackers to inject arbitrary web script or HTML via the portion of the URI after the `;` character, as demonstrated by a URI containing a `snp/snoop.jsp;` sequence.
如何修補 CVE-2007-2449
目前尚未發布修補版本。可考慮移除受影響套件,或參考下方連結中的上游建議。
- Maven/org.apache.tomcat:tomcat—未列出修補版本
CVE-2007-2449 正在被利用嗎?
可能 — EPSS 為 77.4%,屬於高被利用機率區間,建議優先修補。
受影響套件(1)
- >= 4.0.0, <= 4.0.6