CVE-2009-0781: XSS in tomcat6 and tomcat5.5
Bug #341278 reported by
Jamie Strandboge
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
tomcat5.5 (Ubuntu) |
Won't Fix
|
Low
|
Unassigned | ||
Gutsy |
Won't Fix
|
Low
|
Unassigned | ||
Hardy |
Won't Fix
|
Low
|
Unassigned | ||
Intrepid |
Invalid
|
Low
|
Unassigned | ||
Jaunty |
Won't Fix
|
Low
|
Unassigned | ||
tomcat6 (Debian) |
Fix Released
|
Unknown
|
|||
tomcat6 (Ubuntu) |
Fix Released
|
Low
|
Unassigned | ||
Gutsy |
Invalid
|
Undecided
|
Unassigned | ||
Hardy |
Invalid
|
Undecided
|
Unassigned | ||
Intrepid |
Fix Released
|
Low
|
Unassigned | ||
Jaunty |
Fix Released
|
Low
|
Unassigned |
Bug Description
Binary package hint: tomcat6
PublicDate: 2009-03-09
References:
http://
Description:
Cross-site scripting (XSS) vulnerability in jsp/cal/cal2.jsp in the
calendar application in the examples web application in Apache Tomcat 4.1.0
through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18 allows
remote attackers to inject arbitrary web script or HTML via the time
parameter, related to "invalid HTML."
Changed in tomcat6: | |
status: | New → Confirmed |
status: | New → Confirmed |
status: | New → Invalid |
status: | New → Invalid |
Changed in tomcat5.5: | |
status: | New → Confirmed |
status: | New → Confirmed |
status: | New → Confirmed |
status: | New → Confirmed |
Changed in tomcat5.5 (Ubuntu Gutsy): | |
importance: | Undecided → Low |
Changed in tomcat5.5 (Ubuntu Hardy): | |
importance: | Undecided → Low |
Changed in tomcat5.5 (Ubuntu Intrepid): | |
importance: | Undecided → Low |
Changed in tomcat5.5 (Ubuntu Jaunty): | |
importance: | Undecided → Low |
Changed in tomcat6 (Ubuntu Intrepid): | |
importance: | Undecided → Low |
Changed in tomcat6 (Ubuntu Jaunty): | |
importance: | Undecided → Low |
Changed in tomcat6 (Debian): | |
status: | Unknown → Fix Released |
Changed in tomcat6 (Ubuntu): | |
status: | Confirmed → Fix Released |
To post a comment you must log in.
The 18 month support period for Gutsy Gibbon 7.10 has reached its end of life - www.ubuntu. com/news/ ubuntu- 7.10-eol . As a result, we are closing the
http://
Gutsy task.