- 漏洞ID:1176803
- 漏洞类型:跨站脚本
- 发布日期:2011-02-07
- 更新时间:2015-04-13
- CVE编号: CVE-2011-0013
- CNNVD-ID:CNNVD-201102-280
- 漏洞平台: N/A
- CVSS评分:4.3
<a href="https://www.securityfocus.com/bid/46174" target="_blank">https://www.securityfocus.com/bid/46174</a><br/> <a href="https://cxsecurity.com/issue/WLB-2011020161" target="_blank">https://cxsecurity.com/issue/WLB-2011020161</a><br/> <a href="http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-201102-280" target="_blank">http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-201102-280</a><br/>
ApacheSoftwareFoundationTomcat是一款开放源码的JSP应用服务器程序。ApacheSoftwareFoundationTomcat7.0.6之前的7.0版本,5.5.32之前的5.5版本,以及6.0.30之前的6.0版本中存在多个跨站脚本攻击漏洞。远程攻击者可以利用这些漏洞注入任意web脚本或者HTML。
来源:bugzilla.redhat.com
链接:https://bugzilla.redhat.com/show_bug.cgi?id=675786
来源:VUPEN
名称:ADV-2011-0376
链接:http://www.vupen.com/english/advisories/2011/0376
来源:SECTRACK
名称:1025026
链接:http://www.securitytracker.com/id?1025026
来源:BID
名称:46174
链接:http://www.securityfocus.com/bid/46174
来源:BUGTRAQ
名称:20110205[SECURITY]CVE-2011-0013ApacheTomcatManagerXSSvulnerability
链接:http://www.securityfocus.com/archive/1/516209/30/90/threaded
来源:tomcat.apache.org
链接:http://tomcat.apache.org/security-7.html#Fixed_in_Apache_Tomcat_7.0.6_(released_14_Jan_2011)
来源:tomcat.apache.org
链接:http://tomcat.apache.org/security-6.html#Fixed_in_Apache_Tomcat_6.0.30
来源:tomcat.apache.org
链接:http://tomcat.apache.org/security-5.html#Fixed_in_Apache_Tomcat_5.5.32
来源:NSFOCUS
名称:20539
链接:http://www.nsfocus.net/vulndb/20539