CVE-2008-1947

Impact:
Low
Public Date:
2008-06-02
CWE:
CWE-79
Bugzilla:
446393: CVE-2008-1947 Tomcat host manager xss - name field

The MITRE CVE dictionary describes this issue as:

Cross-site scripting (XSS) vulnerability in Apache Tomcat 5.5.9 through 5.5.26 and 6.0.0 through 6.0.16 allows remote attackers to inject arbitrary web script or HTML via the name parameter (aka the hostname attribute) to host-manager/html/add.

Find out more about CVE-2008-1947 from the MITRE CVE dictionary dictionary and NIST NVD.

Red Hat Security Errata

Platform Errata Release Date
Red Hat Developer Suite v.3 (AS v.4) (tomcat5) RHSA-2008:0864 2008-10-02
Red Hat Satellite 5.0 (RHEL v.4 AS) RHSA-2008:1007 2008-12-08
Red Hat Satellite 5.1 (RHEL v.4 AS) (tomcat5) RHSA-2008:1007 2008-12-08
Red Hat Application Server v2 4AS (tomcat5) RHSA-2008:0862 2008-10-02
Red Hat Enterprise Linux 5 (tomcat5) RHSA-2008:0648 2008-08-27

Last Modified

CVE description copyright © 2017, The MITRE Corporation

Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.