NASLDB: Apache Tomcat 6.x < 6.0.30 / 7.x < 7.0.5 Multiple XSS
General
ID: 51526
Name: Apache Tomcat 6.x < 6.0.30 / 7.x < 7.0.5 Multiple XSS
Summary: Checks Apache Tomcat Version
Credits: Tenable Network Security, Inc.
Classification
Risk: –
CVSS: –
CVSS Base Vector: CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N
CVSS Temporal Vector: CVSS2#E:F/RL:OF/RC:C
Port: 8080
Family: Web Servers
Type: Remote
Description
According to its self-reported version number, the instance of Apache
Tomcat listening on the remote host is greater than 6.0.11 and less
than 6.0.30, or is 7.x and less than 7.0.5 and as such, may be
affected by multiple cross-site scripting vulnerabilities.
Several cross-site scripting vulnerabilities exist in the Tomcat
Manager application’s ‘sessionList.jsp’ file. The parameters ‘sort’
and ‘orderby’ are not properly sanitized before being returned to the
user and can be used to inject arbitrary script into the user’s
browser.
Note that Nessus did not actually test for the flaws but instead has
relied on the version in Tomcat’s banner or error page so this may be
a false positive.
Also note, in the case of Tomcat 7.x, successful exploitation requires
that the cross-site request forgery (CSRF) filter is disabled.
Exploiting
Exploit Available: True
Exploitability Ease: Exploits are available
Sources
CVE: CVE-2010-4172
OSVDB: –
Bugtraq: –
scipID: –
Timeline
Vulnerability Disclosure: 2010/11/22
Patch Release: 2011/01/13
Plugin Release: 2011/01/14
Plugin
Version: 1.6
Filename: tomcat_7_0_5.nasl
Filesize: 3979 bytes
MD5 Hash: b54a150f7656b37ffd3f49a0074c332d
Identification: tomcat/"port"/version_source
Require Keys: www/tomcat
Dependencies: "tomcat_error_version.nasl"
Copyright: This script is Copyright© 2011-2012 Tenable Network Security, Inc.
- Latest Plugins
- USN-1611-1 : thunderbird vulnerabilities
- USN-1610-1 : linux vulnerability
- USN-1609-1 : linux-ti-omap4 vulnerability
- SuSE 10 Security Update : PostgreSQL
- RHSA-2012-1364: bind97
- RHSA-2012-1363: bind
- RHSA-2012-1362: thunderbird
- RHSA-2012-1361: xulrunner
- Mandriva Linux Security Advisory : graphicsmagick
- FreeBSD : phpMyAdmin — Multiple XSS due to unescaped HTML output in Trigger, Procedure and Event pages and Fetching the version information from a non-SSL site is vulnerable to a MITM attack













