Core Security
info@coresecurity.com  | +1.617.399.6980 | Contact Us   Core Blog Core Blog Twitter LinkedIn youtube
SHARE

CORE IMPACT v12 - Exploits Update (Wed Nov 16 2011)

Tomcat orderby Cross Site Scripting Exploit

Exploits/Cross Site Scripting (XSS)/Known Vulnerabilities  []




Wed Nov 16 2011
The session list screen (provided by sessionList.jsp) in affected versions uses the orderBy and sort request parameters without applying filtering and therefore is vulnerable to a cross-site scripting attack. Users should be aware that Tomcat 6 does not use httpOnly for session cookies by default so this vulnerability could expose session cookies from the manager application to an attacker.

Exploits Vulnerabiltiy: CVE-2010-4172



< Back to Product Updates