Apache Tomcat Host Manager Servlet跨站脚本执行漏洞

QQ空间 新浪微博 微信 QQ facebook twitter
漏洞ID 1113465 漏洞类型 跨站脚本
发布时间 2007-08-14 更新时间 2009-02-18
CVE编号 CVE-2007-3386 CNNVD-ID CNNVD-200708-229
漏洞平台 Multiple CVSS评分 4.3
|漏洞来源
https://www.exploit-db.com/exploits/30495
https://www.securityfocus.com/bid/25314
https://cxsecurity.com/issue/WLB-2007080077
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200708-229
|漏洞详情
ApacheTomcat是一个流行的开放源码的JSP应用服务器程序。ApacheTomcat实现上存在输入验证漏洞,远程攻击者可能利用引漏洞导致跨站脚本执行。ApacheTomcat的HostManagerServlet没有正确地过滤用户输入,如果用户向服务器提交了恶意请求的话就可以执行跨站脚本攻击,导致注入并执行任意HTML和Web脚本。
|漏洞EXP
source: http://www.securityfocus.com/bid/25314/info

Apache Tomcat Host Manager Servlet is prone to a cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input.

An attacker can exploit this vulnerability to inject HTML and script code into the browser of an unsuspecting victim. The attacker may then steal cookie-based authentication credentials and launch other attacks.

Apache Tomcat 5.5.0 through 5.5.24 and 6.0.0 through 6.0.13 are affected. 

<form action="http://localhost:8080/host-manager/html/add" method="get"> <input type="hidden" NAME='name' VALUE="aaa"> <input type="hidden" NAME='aliases' VALUE="<script>alert()</script>"> <input type="submit"> </form>
|受影响的产品
SuSE SUSE Linux Enterprise Server 10 SP2 Redhat Fedora 7 Redhat Enterprise Linux Desktop Workstation 5 client Redhat Enterprise Linux Desktop 5 client Redhat Enterprise Linux 5 Server
|参考资料

来源:BUGTRAQ
名称:20070814CVE-2007-3386:XSSinHostManager
链接:http://www.securityfocus.com/archive/1/archive/1/476448/100/0/threaded
来源:tomcat.apache.org
链接:http://tomcat.apache.org/security-6.html
来源:FEDORA
名称:FEDORA-2007-3456
链接:https://www.redhat.com/archives/fedora-package-announce/2007-November/msg00525.html
来源:XF
名称:tomcat-hostmanager-alias-xss(36001)
链接:http://xforce.iss.net/xforce/xfdb/36001
来源:BID
名称:25314
链接:http://www.securityfocus.com/bid/25314
来源:BUGTRAQ
名称:20090127CA20090123-01:CohesionTomcatMultipleVulnerabilities(Updated-v1.1)
链接:http://www.securityfocus.com/archive/1/archive/1/500412/100/0/threaded
来源:BUGTRAQ
名称:20090124CA20090123-01:CohesionTomcatMultipleVulnerabilities
链接:http://www.securityfocus.com/archive/1/archive/1/500396/100/0/threaded
来源:REDHAT
名称:RHSA-2007:0871
链接:http://www.redhat.com/support/errata/RHSA-2007-0871.html
来源:VUPEN
名称:ADV-2009-0233
链接:http://www.frsirt.com/english/advisories/2009/0233
来源:VUPEN
名称:ADV-2007-3527
链接:http://www.frsirt.com/english/advisor