Products
White Papers
Data Sheets
Case Studies
Support Login
Locate a Partner
iPolicy Networks Security Advisory
 

Apache Tomcat Host Manager Cross Site Scripting Vulnerability

Date Discovered: 6/4/2008
Severity: High
Applications Affected: Apache Tomcat 5.5.26
Apache Tomcat 5.5.9
Apache Tomcat 6.0.0
Apache Tomcat 6.0.16
Synopsis
Cross-Site Scripting vulnerability has been discovered in Apache Tomcat 6.0.16 and prior. A remote user can execute arbitrary code to the target user's system. Remote attackers can successfully exploit this vulnerability by sending malformed HTML link to the victim, and enticing to victim to open this HTML file or click on the malformed link.
Recommended Actions
Update with latest stable version.
http://tomcat.apache.org/index.html
Threat Analysis
Apache Tomcat is developed at Apache Software Foundation (ASF).Tomcat is a Servlet container which is an implementation of Java Servlet and Java Server Pages technologies. The Java Servlet and Java Server Pages (JSP) specifications are developed under Sun Microsystems Java Community Process. Apache Tomcat powers numerous large and critical web applications across a wide range of organizations and industries.

Cross-Site Scripting vulnerability has been discovered in Apache Tomcat Server in which a remote attacker can inject arbitrary web script via the “name” parameter in the host-manager/html/add. To exploit this issue an attacker sends malformed HTML file or link to victim and enticing him to open that malicious file or click on the link which results arbitrary code execution on the victim machine. After successful exploitation a remote attacker can steal the cookie-based authentication credentials from the victim machine and can make further attack.
References

http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-1947
http://xforce.iss.net/xforce/xfdb/42816
http://www.frsirt.com/english/advisories/2008/1725
http://secunia.com/advisories/30500

Write-up by: Gaurav Bajpai
Security Sites
 
“iPolicy is one of the most visionary firewall vendors in the firewall Magic Quadrant. Its architecture of a central session processing engine and multiple content blades that are able to block based on signatures, rules and so on is the closest to the network security ideal.”
 
Greg Young, John Pescatore
Magic Quadrant for Network Firewalls, 2H04, Gartner
 

 

Home | About Us | Products | Technology | Solutions | Support | Partners | News & Events | Resources | Contact Us
Copyright ©2008 iPolicy Networks - Security Products Division of Tech Mahindra Limited | Privacy Policy | Site Map