Cross-Site Scripting
vulnerability has been discovered in Apache Tomcat 6.0.16 and prior. A
remote user can execute arbitrary code to the target user's system.
Remote attackers can successfully exploit this vulnerability by sending
malformed HTML link to the victim, and enticing to victim to open this
HTML file or click on the malformed link.
Apache Tomcat is developed at Apache Software Foundation (ASF).Tomcat is a Servlet container which is an implementation of Java
Servlet and Java Server Pages technologies. The Java Servlet and Java
Server Pages (JSP) specifications are developed under Sun Microsystems Java Community
Process. Apache Tomcat powers numerous large and critical
web applications across a wide range of organizations and industries.
Cross-Site Scripting vulnerability has been discovered in Apache Tomcat
Server in which a remote attacker can inject arbitrary web script via
the “name” parameter in the host-manager/html/add.
To exploit this issue an attacker sends malformed HTML file or link to
victim and enticing him to open that malicious file or click on the
link which results arbitrary code execution on the victim machine.
After successful exploitation a remote attacker can steal the
cookie-based authentication credentials from the victim machine and can
make further attack.
“iPolicy is one of the most visionary firewall vendors in the firewall Magic Quadrant. Its architecture of a central session processing engine and multiple content blades that are able to block based on signatures, rules and so on is the closest to the network security ideal.”
Greg Young, John Pescatore
Magic Quadrant for Network Firewalls, 2H04, Gartner