CVE-2005-4838

Publication date 31 December 2005

Last updated 24 July 2024


Ubuntu priority

Multiple cross-site scripting (XSS) vulnerabilities in the example web applications for Jakarta Tomcat 5.5.6 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) el/functions.jsp, (2) el/implicit-objects.jsp, and (3) jspx/textRotate.jspx in examples/jsp2/, as demonstrated via script in a request to snp/snoop.jsp. NOTE: other XSS issues in the manager were simultaneously reported, but these require admin access and do not cross privilege boundaries.

Status

No maintained releases are affected by this CVE.

Package Ubuntu Release Status
tomcat5.5 7.04 feisty
Not affected
6.10 edgy
Not affected
6.06 LTS dapper Not in release