Apache.Tomcat.Sendmail.Examples.XSS

description-logoDescription

When reporting error messages, the SendMailServlet in Apache Tomcat does not filter user supplied data before it is displayed. This makes it possible for remote attackers to launch a Cross-site Scripting (XSS) attack.

affected-products-logoAffected Products

The Apache Software Foundation
Versions Affected:
4.0.0 to 4.0.6
4.1.0 to 4.1.36

Impact logoImpact

Cross-Site Scripting.

recomended-action-logoRecommended Actions

Undeploy the "Examples" web application.

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)