CVE-2008-1947
Published: 4 June 2008
Cross-site scripting (XSS) vulnerability in Apache Tomcat 5.5.9 through 5.5.26 and 6.0.0 through 6.0.16 allows remote attackers to inject arbitrary web script or HTML via the name parameter (aka the hostname attribute) to host-manager/html/add.
Priority
Status
Package | Release | Status |
---|---|---|
tomcat5 Launchpad, Ubuntu, Debian |
dapper |
Ignored
(end of life)
|
feisty |
Ignored
(end of life, was needs-triage)
|
|
gutsy |
Does not exist
|
|
hardy |
Does not exist
|
|
intrepid |
Does not exist
|
|
jaunty |
Does not exist
|
|
karmic |
Does not exist
|
|
upstream |
Needs triage
|
|
tomcat5.5 Launchpad, Ubuntu, Debian |
dapper |
Does not exist
|
feisty |
Ignored
(end of life, was needed)
|
|
gutsy |
Ignored
(end of life, was needed)
|
|
hardy |
Released
(5.5.25-5ubuntu1.1)
|
|
intrepid |
Not vulnerable
(5.5.26-3)
|
|
jaunty |
Not vulnerable
(5.5.26-3)
|
|
karmic |
Does not exist
|
|
upstream |
Released
(5.5.26-3)
|
|
Patches: debdiff: http://launchpad.net/bugs/270553 |