~ubuntu-security/ubuntu-cve-tracker/master

« back to all changes in this revision

Viewing changes to retired/CVE-2007-2449

  • Committer: Steve Beattie
  • Date: 2019-02-19 06:18:27 UTC
  • Revision ID: sbeattie@ubuntu.com-20190219061827-oh57fzcfc1u9dlfk
The ubuntu-cve-tracker project has been converted to git.

Please use 'git clone https://git.launchpad.net/ubuntu-cve-tracker' to
get the converted tree.

Show diffs side-by-side

added added

removed removed

Lines of Context:
1
 
PublicDate: 2007-06-14
2
 
Candidate: CVE-2007-2449
3
 
References: 
4
 
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2449
5
 
Description:
6
 
 Multiple cross-site scripting (XSS) vulnerabilities in certain JSP files in
7
 
 the examples web application in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0
8
 
 through 4.1.36, 5.0.0 through 5.0.30, 5.5.0 through 5.5.24, and 6.0.0
9
 
 through 6.0.13 allow remote attackers to inject arbitrary web script or
10
 
 HTML via the portion of the URI after the ';' character, as demonstrated by
11
 
 a URI containing a "snp/snoop.jsp;" sequence.
12
 
Ubuntu-Description: 
13
 
Notes: 
14
 
Bugs: 
15
 
#sid_PKG:
16
 
#dapper_PKG:
17
 
#edgy_PKG:
18
 
#feisty_PKG:
19
 
#devel_PKG:
20
 
dapper_tomcat4: ignored (reached end-of-life)
21
 
edgy_tomcat4: needed (reached end-of-life)
22
 
feisty_tomcat4: DNE
23
 
gutsy_tomcat4: DNE
24
 
hardy_tomcat4: DNE
25
 
intrepid_tomcat4: DNE
26
 
jaunty_tomcat4: DNE
27
 
karmic_tomcat4: DNE
28
 
devel_tomcat4: DNE
29
 
upstream_tomcat4: