Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Apache Tomcat Error Message Reporting Cross Site Scripting Vulnerability

Apache Tomcat is prone to a cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input.

An attacker can exploit this vulnerability to inject HTML and script code into the browser of an unsuspecting victim. The attacker may then steal cookie-based authentication credentials and launch other attacks.

This issue affects Tomcat 3.3 to 3.3.2.







 

Privacy Statement
Copyright 2009, SecurityFocus