CVE-2008-1232
Apache Tomcat Cross-site scripting (XSS) vulnerability
EPSS 75.9%
描述
Cross-site scripting (XSS) vulnerability in Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16 allows remote attackers to inject arbitrary web script or HTML via a crafted string that is used in the message argument to the HttpServletResponse.sendError method.
如何修補 CVE-2008-1232
要修補 CVE-2008-1232,請將受影響套件升級到下列已修補版本。
- Maven/org.apache.tomcat:tomcat—升級至 4.1.38 或更新版本
CVE-2008-1232 正在被利用嗎?
可能 — EPSS 為 75.9%,屬於高被利用機率區間,建議優先修補。
受影響套件(1)
- >= 4.1.0, < 4.1.38