Back to search
CVE-2006-7195
Published: May 9, 2007
Modified: Aug 7, 2024
PUBLISHED
Description
Cross-site scripting (XSS) vulnerability in implicit-objects.jsp in Apache Tomcat 5.0.0 through 5.0.30 and 5.5.0 through 5.5.17 allows remote attackers to inject arbitrary web script or HTML via certain header values.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
28481
vdb-entry
x_refsource_BID
ADV-2008-0065
vdb-entry
x_refsource_VUPEN
20090127 CA20090123-01: Cohesion Tomcat Multiple Vulnerabilities (Updated - v1.1)
mailing-list
x_refsource_BUGTRAQ
33668
third-party-advisory
x_refsource_SECUNIA
20080108 VMSA-2008-0002 Low severity security update for VirtualCenter and ESX Server 3.0.2, and ESX 3.0.1
mailing-list
x_refsource_BUGTRAQ
20090124 CA20090123-01: Cohesion Tomcat Multiple Vulnerabilities
mailing-list
x_refsource_BUGTRAQ
ADV-2007-1729
vdb-entry
x_refsource_VUPEN
ADV-2009-0233
vdb-entry
x_refsource_VUPEN
28365
third-party-advisory
x_refsource_SECUNIA
http://support.avaya.com/elmodocs2/security/ASA-2007-206.htm
x_refsource_CONFIRM
RHSA-2007:0327
vendor-advisory
x_refsource_REDHAT
http://tomcat.apache.org/security-5.html
x_refsource_CONFIRM
oval:org.mitre.oval:def:10514
vdb-entry
signature
x_refsource_OVAL
RHSA-2008:0261
vendor-advisory
x_refsource_REDHAT
http://community.ca.com/blogs/casecurityresponseblog/archive/2009/01/23.aspx
x_refsource_CONFIRM
http://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=197540
x_refsource_CONFIRM
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now