CVE-2007-1358

Aliases:GHSA-xmc9-6p56-3c4v
Advisory lineage Upstream: 0 Downstream: 9
Modified
Published: 09 May 2007, 22:00
Last modified:07 Aug 2024, 12:50

Vulnerability Summary

Overall Risk (default)
low
19/100
CVSS Score
2.6 LOW
v2.0 (nvd)
EPSS Score
44.25% HIGH
44% probability +4.39%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

09 May 2007, 22:00
Published
Vulnerability first disclosed
07 Aug 2024, 12:50
Last Modified
Vulnerability information updated

Description

Cross-site scripting (XSS) vulnerability in certain applications using Apache Tomcat 4.0.0 through 4.0.6 and 4.1.0 through 4.1.34 allows remote attackers to inject arbitrary web script or HTML via crafted "Accept-Language headers that do not conform to RFC 2616".

CVSS Metrics

  • v2.0LOWScore: 2.6AV:N/AC:H/Au:N/C:N/I:P/A:N

EPSS Trends

Current EPSS score: 44.25% Percentile: 98%

Techniques & Countermeasures

  • CWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

    The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Affected Systems

  • UnknownTomcat

    ≤ 4.1.31 | 4.0.0 | 4.0.1 | 4.0.2 | 4.0.3 | 4.0.4 | 4.0.5 | 4.0.6 | 4.1.0

  • org.apache.tomcattomcat

    ≥ 4.0.0, ≤ 4.0.6 | ≥ 4.1.0, ≤ 4.1.34

References (42)