Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2010-4172Cross-site Scripting in Apache Tomcat

CWE-79Cross-site Scripting12 documents9 sources
Severity
4.3MEDIUMNVD
EPSS
11.9%
top 6.24%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedNov 26
Latest updateMay 14

Description

Multiple cross-site scripting (XSS) vulnerabilities in the Manager application in Apache Tomcat 6.0.12 through 6.0.29 and 7.0.0 through 7.0.4 allow remote attackers to inject arbitrary web script or HTML via the (1) orderBy or (2) sort parameter to sessionsList.jsp, or unspecified input to (3) sessionDetail.jsp or (4) java/org/apache/catalina/manager/JspHelper.java, related to use of untrusted web applications.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages1 packages

NVDapache/tomcat19 versions+18

Patches

🔴Vulnerability Details

3
OSV
Improper Neutralization of Input During Web Page Generation in Apache Tomcat2022-05-14
GHSA
Improper Neutralization of Input During Web Page Generation in Apache Tomcat2022-05-14
CVEList
CVE-2010-4172: Multiple cross-site scripting (XSS) vulnerabilities in the Manager application in Apache Tomcat 62010-11-26

💥Exploits & PoCs

1
Exploit-DB
Apache Tomcat 7.0.4 - 'sort' / 'orderBy' Cross-Site Scripting2010-11-22

🔍Detection Rules

2
Suricata
ET WEB_SPECIFIC_APPS Apache Tomcat Sort Parameter Cross Site Scripting Attempt2011-06-24
Suricata
ET WEB_SPECIFIC_APPS Apache Tomcat Orderby Parameter Cross Site Scripting Attempt2011-06-24

📋Vendor Advisories

2
Ubuntu
Tomcat vulnerability2011-01-24
Red Hat
tomcat: cross-site-scripting vulnerability in the manager application2010-11-22

💬Community

3
Bugzilla
CVE-2010-4172 tomcat: cross-site-scripting vulnerability in the manager application [fedora-all]2011-01-13
Bugzilla
CVE-2010-4312 tomcat6: does not use HTTPOnly for session cookies by default2010-11-29
Bugzilla
CVE-2010-4172 tomcat: cross-site-scripting vulnerability in the manager application2010-11-23
CVE-2010-4172 — Cross-site Scripting in Apache Tomcat | cvebase