[Forgot Password]
Login  Register Subscribe

30389

 
 

423868

 
 

242976

 
 

909

 
 

192814

 
 

277

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2009-0781Date: (C)2009-03-09   (M)2023-12-22


Cross-site scripting (XSS) vulnerability in jsp/cal/cal2.jsp in the calendar application in the examples web application in Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18 allows remote attackers to inject arbitrary web script or HTML via the time parameter, related to "invalid HTML."

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 4.3
Exploit Score: 8.6
Impact Score: 2.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: MEDIUM
Authentication: NONE
Confidentiality: NONE
Integrity: PARTIAL
Availability: NONE
  
Reference:
http://www.securityfocus.com/archive/1/501538/100/0/threaded
http://www.securityfocus.com/archive/1/507985/100/0/threaded
SUNALERT-263529
SECUNIA-35685
SECUNIA-35788
SECUNIA-37460
SECUNIA-42368
ADV-2009-1856
ADV-2009-3316
ADV-2010-3056
APPLE-SA-2010-03-29-1
DSA-2207
FEDORA-2009-11352
FEDORA-2009-11356
FEDORA-2009-11374
HPSBMA02535
HPSBOV02762
HPSBUX02579
HPSBUX02860
MDVSA-2009:136
MDVSA-2009:138
SUSE-SR:2009:012
http://support.apple.com/kb/HT4077
http://tomcat.apache.org/security-4.html
http://tomcat.apache.org/security-5.html
http://tomcat.apache.org/security-6.html
http://www.vmware.com/security/advisories/VMSA-2009-0016.html
https://lists.apache.org/thread.html/06cfb634bc7bf37af7d8f760f118018746ad8efbd519c4b789ac9c2e%40%3Cdev.tomcat.apache.org%3E
https://lists.apache.org/thread.html/29dc6c2b625789e70a9c4756b5a327e6547273ff8bde7e0327af48c5%40%3Cdev.tomcat.apache.org%3E
https://lists.apache.org/thread.html/8dcaf7c3894d66cb717646ea1504ea6e300021c85bb4e677dc16b1aa%40%3Cdev.tomcat.apache.org%3E
https://lists.apache.org/thread.html/c62b0e3a7bf23342352a5810c640a94b6db69957c5c19db507004d74%40%3Cdev.tomcat.apache.org%3E
https://lists.apache.org/thread.html/r3aacc40356defc3f248aa504b1e48e819dd0471a0a83349080c6bcbf%40%3Cdev.tomcat.apache.org%3E
https://lists.apache.org/thread.html/r584a714f141eff7b1c358d4679288177bd4ca4558e9999d15867d4b5%40%3Cdev.tomcat.apache.org%3E
https://lists.apache.org/thread.html/rb71997f506c6cc8b530dd845c084995a9878098846c7b4eacfae8db3%40%3Cdev.tomcat.apache.org%3E
oval:org.mitre.oval:def:11041
oval:org.mitre.oval:def:19345
oval:org.mitre.oval:def:6564
tomcat-cal2-xss(49213)

CWE    1
CWE-79
OVAL    15
oval:org.secpod.oval:def:102261
oval:org.secpod.oval:def:102212
oval:org.secpod.oval:def:700303
oval:org.secpod.oval:def:301232
...

© SecPod Technologies