CVE-2007-4724

Publication date 5 September 2007

Last updated 17 July 2025


Ubuntu priority

Description

Cross-site request forgery (CSRF) vulnerability in cal2.jsp in the calendar examples application in Apache Tomcat 4.1.31 allows remote attackers to add events as arbitrary users via the time and description parameters.

Status

Package Ubuntu Release Status
tomcat5.5 7.04 feisty
Not affected
6.10 edgy
Not affected
6.06 LTS dapper Not in release


Access our resources on patching vulnerabilities