Red Hat Customer Portal

Skip to main content

CVE-2006-7196

Impact:
Moderate
Public Date:
2007-04-26
CWE:
CWE-79
Bugzilla:
238131: CVE-2006-7196 tomcat XSS in example webapps

The MITRE CVE dictionary describes this issue as:

Cross-site scripting (XSS) vulnerability in the calendar application example in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.31, 5.0.0 through 5.0.30, and 5.5.0 through 5.5.15 allows remote attackers to inject arbitrary web script or HTML via the time parameter to cal2.jsp and possibly unspecified other vectors. NOTE: this may be related to CVE-2006-0254.1.

Find out more about CVE-2006-7196 from the MITRE CVE dictionary dictionary and NIST NVD.

Red Hat Security Errata

Platform Errata Release Date
Red Hat Satellite 5.0 (RHEL v.4 AS) RHSA-2008:0261 2008-05-20
Red Hat Application Server v2 4AS (jakarta-commons-modeler) RHSA-2007:0326 2007-05-21
Red Hat Application Server 3AS (tomcat5) RHSA-2007:0340 2007-05-08
Red Hat Satellite v 4.2 (RHEL v.4 AS) RHSA-2008:0524 2008-06-30
Red Hat Satellite v 4.2 (RHEL v.3 AS) RHSA-2008:0524 2008-06-30

Last Modified