[SECURITY] Cross site scripting vulnerability revealed in 'examples' webapp of Apache Tomcat

"Remy Maucherat" <[email protected]>
Newsgroups gmane.comp.jakarta.announcements
Message-ID <[email protected]>
Cross Site scripting security vulnerabilities exist in the 'examples' web
application which is distributed along with Apache Tomcat. This affects all
released versions of Tomcat, including 3.x and 4.x.

No other components of Tomcat are currently known to be vulnerable to cross
site scripting.

To address this security issue, administrators of public servers which have
deployed Apache Tomcat should make sure the 'examples' webapp is removed
from the deployed Tomcat installation.
The 'examples' webapp will be modified in future Apache Tomcat releases to
prevent cross site scripting.

Background information on cross site scripting: This allows a mailicious
website to execute JavaScript code using the security policy of a trusted
domain.
More information: http://httpd.apache.org/info/css-security/

Remy and Larry
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.