Public Date:
247994: CVE-2007-3386 tomcat host manager xss

The MITRE CVE dictionary describes this issue as:

Cross-site scripting (XSS) vulnerability in the Host Manager Servlet for Apache Tomcat 6.0.0 to 6.0.13 and 5.5.0 to 5.5.24 allows remote attackers to inject arbitrary HTML and web script via crafted requests, as demonstrated using the aliases parameter to an html/add action.

Find out more about CVE-2007-3386 from the MITRE CVE dictionary dictionary and NIST NVD.

Red Hat Security Errata

Platform Errata Release Date
Red Hat Application Server v2 4AS (tomcat5) RHSA-2007:0876 2007-10-11
Red Hat Enterprise Linux version 5 (tomcat5) RHSA-2007:0871 2007-09-26