Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2008-1232Cross-site Scripting in Apache Tomcat

Severity
4.3MEDIUMNVD
EPSS
38.1%
top 2.77%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedAug 4
Latest updateMay 1

Description

Cross-site scripting (XSS) vulnerability in Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16 allows remote attackers to inject arbitrary web script or HTML via a crafted string that is used in the message argument to the HttpServletResponse.sendError method.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages1 packages

NVDapache/tomcat4.1.04.1.37+2

Patches

🔴Vulnerability Details

3
OSV
Apache Tomcat Cross-site scripting (XSS) vulnerability2022-05-01
GHSA
Apache Tomcat Cross-site scripting (XSS) vulnerability2022-05-01
CVEList
CVE-2008-1232: Cross-site scripting (XSS) vulnerability in Apache Tomcat 42008-08-04

💥Exploits & PoCs

1
Exploit-DB
Apache Tomcat 6.0.16 - 'HttpServletResponse.sendError()' Cross-Site Scripting2008-08-01

📋Vendor Advisories

1
Red Hat
tomcat: Cross-Site-Scripting enabled by sendError call2008-08-01

💬Community

1
Bugzilla
CVE-2008-1232 tomcat: Cross-Site-Scripting enabled by sendError call2008-08-01
CVE-2008-1232 — Cross-site Scripting in Apache Tomcat | cvebase