01642 06 11 11 Arrange Call

Multiple Cross-Site Scripting (XSS) Vulnerabilities in Apache Tomcat Manager Application

CVE-2010-4172 · MEDIUM

CVE-2010-4172

Multiple cross-site scripting (XSS) vulnerabilities in the Manager application in Apache Tomcat 6.0.12 through 6.0.29 and 7.0.0 through 7.0.4 allow remote attackers to inject arbitrary web script or HTML via the (1) orderBy or (2) sort parameter to sessionsList.jsp, or unspecified input to (3) sessionDetail.jsp or (4) java/org/apache/catalina/manager/JspHelper.java, related to use of untrusted web applications.

Learn more about our Cis Benchmark Audit For Apache Http Server.