CORE IMPACT v12 - Exploits Update (Wed Nov 16 2011)
Tomcat orderby Cross Site Scripting Exploit
Exploits/Cross Site Scripting (XSS)/Known Vulnerabilities []
Wed Nov 16 2011
The session list screen (provided by sessionList.jsp) in affected versions uses the orderBy and sort request parameters without applying filtering and therefore is vulnerable to a cross-site scripting attack. Users should be aware that Tomcat 6 does not use httpOnly for session cookies by default so this vulnerability could expose session cookies from the manager application to an attacker.
Exploits Vulnerabiltiy: CVE-2010-4172











