CVE
- Id
- 23299
- CVE No.
- CVE-2006-7195
- Status
- Candidate
- Description
- Cross-site scripting (XSS) vulnerability in implicit-objects.jsp in Apache Tomcat 5.0.0 through 5.0.30 and 5.5.0 through 5.5.17 allows remote attackers to inject arbitrary web script or HTML via certain header values.
- Phase
- Assigned (20070418)
- Votes
- None (candidate not yet proposed)
- Comments
Related CVE References
Id | CVE Id | CVE No. | Reference | Actions |
---|---|---|---|---|
224195 | 23299 | CVE-2006-7195 | BUGTRAQ:20080108 VMSA-2008-0002 Low severity security update for VirtualCenter and ESX Server 3.0.2, and ESX 3.0.1 | View |
224196 | 23299 | CVE-2006-7195 | URL:http://www.securityfocus.com/archive/1/archive/1/485938/100/0/threaded | View |
224197 | 23299 | CVE-2006-7195 | BUGTRAQ:20090127 CA20090123-01: Cohesion Tomcat Multiple Vulnerabilities (Updated - v1.1) | View |
224198 | 23299 | CVE-2006-7195 | URL:http://www.securityfocus.com/archive/1/archive/1/500412/100/0/threaded | View |
224199 | 23299 | CVE-2006-7195 | BUGTRAQ:20090124 CA20090123-01: Cohesion Tomcat Multiple Vulnerabilities | View |
224200 | 23299 | CVE-2006-7195 | URL:http://www.securityfocus.com/archive/1/archive/1/500396/100/0/threaded | View |
224201 | 23299 | CVE-2006-7195 | MLIST:[Security-announce] 20080107 VMSA-2008-0002 Low severity security update for VirtualCenter and ESX Server 3.0.2, and ESX 3.0.1 | View |
224202 | 23299 | CVE-2006-7195 | URL:http://lists.vmware.com/pipermail/security-announce/2008/000003.html | View |
224203 | 23299 | CVE-2006-7195 | CONFIRM:http://tomcat.apache.org/security-5.html | View |
224204 | 23299 | CVE-2006-7195 | CONFIRM:http://support.avaya.com/elmodocs2/security/ASA-2007-206.htm | View |
224205 | 23299 | CVE-2006-7195 | CONFIRM:http://community.ca.com/blogs/casecurityresponseblog/archive/2009/01/23.aspx | View |
224206 | 23299 | CVE-2006-7195 | CONFIRM:http://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=197540 | View |
224207 | 23299 | CVE-2006-7195 | REDHAT:RHSA-2007:0327 | View |
224208 | 23299 | CVE-2006-7195 | URL:http://www.redhat.com/support/errata/RHSA-2007-0327.html | View |
224209 | 23299 | CVE-2006-7195 | REDHAT:RHSA-2008:0261 | View |
224210 | 23299 | CVE-2006-7195 | URL:http://www.redhat.com/support/errata/RHSA-2008-0261.html | View |
224211 | 23299 | CVE-2006-7195 | BID:28481 | View |
224212 | 23299 | CVE-2006-7195 | URL:http://www.securityfocus.com/bid/28481 | View |
224213 | 23299 | CVE-2006-7195 | OVAL:oval:org.mitre.oval:def:10514 | View |
224214 | 23299 | CVE-2006-7195 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10514 | View |
224215 | 23299 | CVE-2006-7195 | VUPEN:ADV-2007-1729 | View |
224216 | 23299 | CVE-2006-7195 | URL:http://www.vupen.com/english/advisories/2007/1729 | View |
224217 | 23299 | CVE-2006-7195 | VUPEN:ADV-2008-0065 | View |
224218 | 23299 | CVE-2006-7195 | URL:http://www.vupen.com/english/advisories/2008/0065 | View |
224219 | 23299 | CVE-2006-7195 | VUPEN:ADV-2009-0233 | View |
224220 | 23299 | CVE-2006-7195 | URL:http://www.vupen.com/english/advisories/2009/0233 | View |
224221 | 23299 | CVE-2006-7195 | SECUNIA:28365 | View |
224222 | 23299 | CVE-2006-7195 | URL:http://secunia.com/advisories/28365 | View |
224223 | 23299 | CVE-2006-7195 | SECUNIA:33668 | View |
Related JVN
Id | JVN No. | Title | Summary | CVE No. | CVE Id | CVSS_v2 | CVSS_v3 | JVN URL | Actions |
---|---|---|---|---|---|---|---|---|---|
59601 | JVNDB-2006-001867 | Apache Tomca の AJP コネクタにおける重要なメモリの一部を読まれる脆弱性 | Apache Tomca の AJP コネクタは、チャンクに不適切な長さを使用するため mod_jk 内の ajp_process_callback でバッファオーバーリードを引き起こし、重要なメモリの一部を読まれる脆弱性が存在します。 | CVE-2006-7197 | 23299 | 7.8 | http://jvndb.jvn.jp/ja/contents/2006/JVNDB-2006-001867.html | View |