- 漏洞ID:1106936
- 漏洞类型:其他
- 发布日期:2002-08-21
- 更新时间:2003-10-06
- CVE编号: CVE-2002-1567
- CNNVD-ID:CNNVD-200310-009
- 漏洞平台:Unix
- CVSS评分:6.8
<a href="https://www.exploit-db.com/exploits/21734" target="_blank">https://www.exploit-db.com/exploits/21734</a><br/> <a href="https://www.securityfocus.com/bid/82870" target="_blank">https://www.securityfocus.com/bid/82870</a><br/> <a href="http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200310-009" target="_blank">http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200310-009</a><br/>
Apache Tomcat 4.1版本存在跨站脚本(XSS)漏洞。远程攻击者借助带有编码换行符的URL执行任意web脚本和盗取cookies,该换行符后面接有名字包含脚本的.jsp文件请求。
来源:VULN-DEV
名称:20020821ApacheTomcat4.1Cross-SiteScriptingVulnerability
链接:http://archives.neohapsis.com/archives/vuln-dev/2002-q3/0482.html
来源:tomcat.apache.org
链接:http://tomcat.apache.org/security-4.html