The Tomcat security team reports:
The HTML Manager interface displayed web applciation provided data, such as display names, without filtering. A malicious web application could trigger script execution by an administartive user when viewing the manager pages. [source]
The HTML Manager interface displayed web applciation provided data, such as display names, without filtering. A malicious web application could trigger script execution by an administartive user when viewing the manager pages.
Copyright © 2003-2005 Jacques Vidrine and contributors. Please see the source of this document for full copyright information.