Apache Tomcat 5.5.x < 5.5.32 HTML Manager Interface XSS

medium Nessus Network Monitor Plugin ID 5787

Synopsis

The remote web server is affected by a cross-site scripting vulnerability.

Description

According to its self-reported version number, the instance of Apache Tomcat 5.5.x listening on the remote host is prior to 5.5.32. It is, therefore, affected by a cross-site scripting vulnerability in its HTML Manager interface.

An input validation error exists in the HTML Manager interface of Tomcat that may allow a remote attacker to inject code into a user's browser via a crafted URL.

Note that Nessus Network Monitor has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

Upgrade to Apache Tomcat 5.5.32 or later.

See Also

http://tomcat.apache.org/security-5.html

http://tomcat.apache.org/security-5.html#Fixed_in_Apache_Tomcat_5.5.32

Plugin Details

Severity: Medium

ID: 5787

Family: Web Servers

Published: 2/11/2011

Updated: 3/6/2019

Nessus ID: 51957

Risk Information

Risk Factor: Medium

CVSS v2.0

Base Score: 4.3

Temporal Score: 3.2

Vector: CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N

Temporal Vector: CVSS2#E:U/RL:OF/RC:C

Vulnerability Information

CPE: cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*

Patch Publication Date: 2/1/2011

Vulnerability Publication Date: 2/4/2011

Reference Information

CVE: CVE-2011-0013

BID: 46174