Skip to content

Cross-site scripting in Apache Tomcat

Moderate severity GitHub Reviewed Published May 1, 2022 to the GitHub Advisory Database • Updated Feb 14, 2023

Package

maven org.apache.tomcat:tomcat (Maven)

Affected versions

>= 4.0.0, < 4.0.7
>= 4.1.0, < 4.1.32
>= 5.0.0, < 5.0.31
>= 5.5.0, < 5.5.16

Patched versions

4.0.7
4.1.32
5.0.31
5.5.16

Description

Cross-site scripting (XSS) vulnerability in the calendar application example in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.31, 5.0.0 through 5.0.30, and 5.5.0 through 5.5.15 allows remote attackers to inject arbitrary web script or HTML via the time parameter to cal2.jsp and possibly unspecified other vectors. NOTE: this may be related to CVE-2006-0254.1.

References

Published by the National Vulnerability Database May 10, 2007
Published to the GitHub Advisory Database May 1, 2022
Reviewed Feb 14, 2023
Last updated Feb 14, 2023

Severity

Moderate

Weaknesses

CVE ID

CVE-2006-7196

GHSA ID

GHSA-pm78-wxxf-fw98

Source code

Checking history
See something to contribute? Suggest improvements for this vulnerability.