CVE-2006-7195
Description
Cross-site scripting (XSS) vulnerability in implicit-objects.jsp in Apache Tomcat 5.0.0 through 5.0.30 and 5.5.0 through 5.5.17 allows remote attackers to inject arbitrary web script or HTML via certain header values.
Risk Information
Base Score
8.6
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N/E:U/RL:O/RC:C
EPSS Score
Exploitation Probability
10.881
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| Update Tomcat to 9.5.14 | Windows |
| Update Tomcat to 9.5.5 | Windows |
| Update Tomcat to 9.5.7 | Windows |
| Update Tomcat to 9.5.8 | Windows |
| Update Tomcat to 9.6.10 | Windows |
| Update Tomcat to 9.6.3 | Windows |
| Update Tomcat to 9.6.4 | Windows |
| Update Tomcat to 9.6.7 | Windows |
| Update Tomcat to 9.6.8 | Windows |
| Update Tomcat to 2.4.5 | Windows |
| Update Tomcat to 3.0.14 | Windows |
| Update Apache Tomcat to 5.5.18 | Windows |
| Update Apache Tomcat to 5.5.17 | Windows |
| Vulnerabilities CVE-2006-7195 are fixed in Apache - tomcat 5.5.18 | Windows |
| Vulnerabilities CVE-2006-7195 are affected in Apache - tomcat 5.0.30 | Windows |
| (RHSA-2007:0327) Important: tomcat security update jakarta-commons-modeler-1.1-8jpp.1.0.2.el5.i386.rpm | Linux |
| (RHSA-2007:0327) Important: tomcat security update jakarta-commons-modeler-1.1-8jpp.1.0.2.el5.x86_64.rpm | Linux |
| (RHSA-2007:0327) Important: tomcat security update jakarta-commons-modeler-javadoc-1.1-8jpp.1.0.2.el5.i386.rpm | Linux |
| (RHSA-2007:0327) Important: tomcat security update jakarta-commons-modeler-javadoc-1.1-8jpp.1.0.2.el5.x86_64.rpm | Linux |
| Update Tomcat to 9.5.14 (For Linux) | Linux |
| Update Tomcat to 9.5.5 (For Linux) | Linux |
| Update Tomcat to 9.5.7 (For Linux) | Linux |
| Update Tomcat to 9.5.8 (For Linux) | Linux |
| Update Tomcat to 9.6.10 (For Linux) | Linux |
| Update Tomcat to 9.6.3 (For Linux) | Linux |
| Update Tomcat to 9.6.4 (For Linux) | Linux |
| Update Tomcat to 9.6.7 (For Linux) | Linux |
| Update Tomcat to 9.6.8 (For Linux) | Linux |
| Update Tomcat to 2.4.5 (For Linux) | Linux |
| Update Tomcat to 3.0.14 (For Linux) | Linux |
| Update Apache Tomcat to 5.5.18 (For Linux) | Linux |
| Update Apache Tomcat to 5.5.17 (For Linux) | Linux |
| Vulnerabilities CVE-2006-7195 are fixed in Apache - tomcat for Linux 5.5.18 | Linux |
| Vulnerabilities CVE-2006-7195 are affected in Apache - tomcat for Linux 5.0.30 | Linux |
Patch Details
No records foundReferences
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234