CVE-2005-4838

Publication date 31 December 2005

Last updated 4 August 2025


Ubuntu priority

Description

Multiple cross-site scripting (XSS) vulnerabilities in the example web applications for Jakarta Tomcat 5.5.6 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) el/functions.jsp, (2) el/implicit-objects.jsp, and (3) jspx/textRotate.jspx in examples/jsp2/, as demonstrated via script in a request to snp/snoop.jsp. NOTE: other XSS issues in the manager were simultaneously reported, but these require admin access and do not cross privilege boundaries.

Status

Package Ubuntu Release Status
tomcat5.5 7.04 feisty
Not affected
6.10 edgy
Not affected
6.06 LTS dapper Not in release


Access our resources on patching vulnerabilities