CVE-2007-1355

Description

Multiple cross-site scripting (XSS) vulnerabilities in the appdev/sample/web/hello.jsp example application in Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.36, 5.0.0 through 5.0.30, 5.5.0 through 5.5.23, and 6.0.0 through 6.0.10 allow remote attackers to inject arbitrary web script or HTML via the test parameter and unspecified vectors.

Risk Information

Base Score
8.6
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N/E:P/RL:O/RC:C
EPSS Score
Exploitation Probability
83.3

Associated Vulnerability

VulnerabilityOS Platform
Update Tomcat to 9.5.14Windows
Update Tomcat to 9.5.5Windows
Update Tomcat to 9.5.7Windows
Update Tomcat to 9.5.8Windows
Update Tomcat to 9.6.10Windows
Update Tomcat to 9.6.3Windows
Update Tomcat to 9.6.4Windows
Update Tomcat to 9.6.7Windows
Update Tomcat to 9.6.8Windows
Update Tomcat to 2.4.5Windows
Update Tomcat to 3.0.14Windows
Update Apache Tomcat to 5.5.24Windows
Update Apache Tomcat to 5.5.23Windows
Vulnerabilities CVE-2007-1355 are fixed in Apache - jsp-api 4.1.37Windows
Vulnerabilities CVE-2007-1355 are fixed in Apache - jsp-api 5.5.24Windows
Vulnerabilities CVE-2007-1355 are fixed in Apache - jsp-api 6.0.11Windows
Vulnerabilities CVE-2007-1355 are affected in Apache - jsp-api 5.0.30Windows
Vulnerabilities CVE-2007-1355 are fixed in Apache - servlet-api 4.1.37Windows
Vulnerabilities CVE-2007-1355 are fixed in Apache - servlet-api 5.5.24Windows
Vulnerabilities CVE-2007-1355 are fixed in Apache - servlet-api 6.0.11Windows
Vulnerabilities CVE-2007-1355 are affected in Apache - servlet-api 5.0.30Windows
Update Tomcat to 9.5.14 (For Linux)Linux
Update Tomcat to 9.5.5 (For Linux)Linux
Update Tomcat to 9.5.7 (For Linux)Linux
Update Tomcat to 9.5.8 (For Linux)Linux
Update Tomcat to 9.6.10 (For Linux)Linux
Update Tomcat to 9.6.3 (For Linux)Linux
Update Tomcat to 9.6.4 (For Linux)Linux
Update Tomcat to 9.6.7 (For Linux)Linux
Update Tomcat to 9.6.8 (For Linux)Linux
Update Tomcat to 2.4.5 (For Linux)Linux
Update Tomcat to 3.0.14 (For Linux)Linux
Update Apache Tomcat to 5.5.24 (For Linux)Linux
Update Apache Tomcat to 5.5.23 (For Linux)Linux
Vulnerabilities CVE-2007-1355 are fixed in Apache - jsp-api for Linux 4.1.37Linux
Vulnerabilities CVE-2007-1355 are fixed in Apache - jsp-api for Linux 5.5.24Linux
Vulnerabilities CVE-2007-1355 are fixed in Apache - jsp-api for Linux 6.0.11Linux
Vulnerabilities CVE-2007-1355 are affected in Apache - jsp-api for Linux 5.0.30Linux
Vulnerabilities CVE-2007-1355 are fixed in Apache - servlet-api for Linux 4.1.37Linux
Vulnerabilities CVE-2007-1355 are fixed in Apache - servlet-api for Linux 5.5.24Linux
Vulnerabilities CVE-2007-1355 are fixed in Apache - servlet-api for Linux 6.0.11Linux
Vulnerabilities CVE-2007-1355 are affected in Apache - servlet-api for Linux 5.0.30Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234