CVE-2007-1355
Description
Multiple cross-site scripting (XSS) vulnerabilities in the appdev/sample/web/hello.jsp example application in Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.36, 5.0.0 through 5.0.30, 5.5.0 through 5.5.23, and 6.0.0 through 6.0.10 allow remote attackers to inject arbitrary web script or HTML via the test parameter and unspecified vectors.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Multiple XSS vulnerabilities in the Apache Tomcat hello.jsp example application allow remote attackers to inject arbitrary web script or HTML via the test parameter.
Vulnerability
Multiple cross-site scripting (XSS) vulnerabilities exist in the appdev/sample/web/hello.jsp example application shipped with Apache Tomcat. The flaw is present in versions 4.0.0 through 4.0.6, 4.1.0 through 4.1.36, 5.0.0 through 5.0.30, 5.5.0 through 5.5.23, and 6.0.0 through 6.0.10 [1][2][3]. The vulnerability can be triggered via the test parameter and other unspecified vectors.
Exploitation
An attacker can exploit this vulnerability by crafting a malicious URL containing JavaScript or HTML in the test parameter of the hello.jsp page. The request is sent to a vulnerable Tomcat server, and because the example application does not properly sanitize user input, the injected script is rendered in the victim's browser when they access the crafted link. No authentication is required, and the attacker only needs to trick a user into visiting the malicious URL (e.g., via phishing or embedding the link on another site) [1][2][3].
Impact
Successful exploitation allows a remote attacker to execute arbitrary web script or HTML in the context of the victim's browser session, within the domain of the affected Tomcat server. This can lead to session hijacking, credential theft, defacement, or redirection to malicious sites. The vulnerability impacts confidentiality and integrity of user data exposed through the browser, but does not directly affect the server-side application or data [3].
Mitigation
Apache Tomcat has reached end-of-life for many of the affected branches, including 4.x, 5.0.x, 5.5.x, and 6.0.x, and no patches will be provided [1][2]. Users are strongly advised to remove or disable the hello.jsp example application from production deployments. For still-supported branches (none at this time), upgrading to a fixed version (e.g., 5.5.26 or later, 6.0.11 or later) would resolve the issue [1][2][3]. As a general best practice, example applications should not be deployed in production environments.
AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.apache.tomcat:jsp-apiMaven | >= 4.1.0, < 4.1.37 | 4.1.37 |
org.apache.tomcat:jsp-apiMaven | >= 5.5.0, < 5.5.24 | 5.5.24 |
org.apache.tomcat:jsp-apiMaven | >= 6.0.0, < 6.0.11 | 6.0.11 |
org.apache.tomcat:jsp-apiMaven | >= 5.0.0, <= 5.0.30 | — |
org.apache.tomcat:jsp-apiMaven | >= 4.0.0, <= 4.0.6 | — |
org.apache.tomcat:servlet-apiMaven | >= 4.1.0, < 4.1.37 | 4.1.37 |
org.apache.tomcat:servlet-apiMaven | >= 5.5.0, < 5.5.24 | 5.5.24 |
org.apache.tomcat:servlet-apiMaven | >= 6.0.0, < 6.0.11 | 6.0.11 |
org.apache.tomcat:servlet-apiMaven | >= 5.0.0, <= 5.0.30 | — |
org.apache.tomcat:servlet-apiMaven | >= 4.0.0, <= 4.0.6 | — |
Affected products
54cpe:2.3:a:apache:tomcat:4.0.0:*:*:*:*:*:*:*+ 51 more
- cpe:2.3:a:apache:tomcat:4.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:4.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:4.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:4.0.3:*:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:4.0.4:*:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:4.0.5:*:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:4.0.6:*:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:4.1.10:*:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:4.1.15:*:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:4.1.24:*:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:4.1.28:*:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:4.1.31:*:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:5.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:5.0.10:*:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:5.0.11:*:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:5.0.12:*:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:5.0.13:*:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:5.0.14:*:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:5.0.15:*:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:5.0.16:*:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:5.0.17:*:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:5.0.18:*:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:5.0.19:*:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:5.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:5.0.21:*:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:5.0.22:*:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:5.0.23:*:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:5.0.24:*:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:5.0.25:*:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:5.0.26:*:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:5.0.27:*:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:5.0.28:*:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:5.0.29:*:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:5.0.3:*:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:5.0.30:*:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:5.0.4:*:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:5.0.5:*:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:5.0.6:*:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:5.0.7:*:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:5.0.8:*:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:5.0.9:*:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:6.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:6.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:6.0.10:*:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:6.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:6.0.3:*:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:6.0.4:*:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:6.0.5:*:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:6.0.6:*:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:6.0.7:*:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:6.0.8:*:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:6.0.9:*:*:*:*:*:*:*
- ghsa-coords2 versions
>= 4.1.0, < 4.1.37+ 1 more
- (no CPE)range: >= 4.1.0, < 4.1.37
- (no CPE)range: >= 4.1.0, < 4.1.37
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
39- www.securityfocus.com/bid/24058nvdExploitPatch
- github.com/advisories/GHSA-4c6x-gfc8-c26rghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2007-1355ghsaADVISORY
- community.ca.com/blogs/casecurityresponseblog/archive/2009/01/23.aspxnvdWEB
- h20000.www2.hp.com/bizsupport/TechSupport/Document.jspnvdWEB
- lists.apple.com/archives/security-announce/2008//Jun/msg00002.htmlnvdWEB
- rhn.redhat.com/errata/RHSA-2008-0630.htmlnvdWEB
- sunsolve.sun.com/search/document.donvdWEB
- support.apple.com/kb/HT2163nvdWEB
- support.ca.com/irj/portal/anonymous/phpsupcontentnvdWEB
- tomcat.apache.org/security-4.htmlnvdWEB
- tomcat.apache.org/security-5.htmlnvdWEB
- tomcat.apache.org/security-6.htmlnvdWEB
- www.redhat.com/support/errata/RHSA-2008-0261.htmlnvdWEB
- exchange.xforce.ibmcloud.com/vulnerabilities/34377nvdWEB
- lists.apache.org/thread.html/29dc6c2b625789e70a9c4756b5a327e6547273ff8bde7e0327af48c5%40%3Cdev.tomcat.apache.org%3EnvdWEB
- lists.apache.org/thread.html/29dc6c2b625789e70a9c4756b5a327e6547273ff8bde7e0327af48c5@%3Cdev.tomcat.apache.org%3EghsaWEB
- lists.apache.org/thread.html/c62b0e3a7bf23342352a5810c640a94b6db69957c5c19db507004d74%40%3Cdev.tomcat.apache.org%3EnvdWEB
- lists.apache.org/thread.html/c62b0e3a7bf23342352a5810c640a94b6db69957c5c19db507004d74@%3Cdev.tomcat.apache.org%3EghsaWEB
- lists.apache.org/thread.html/rb71997f506c6cc8b530dd845c084995a9878098846c7b4eacfae8db3%40%3Cdev.tomcat.apache.org%3EnvdWEB
- lists.apache.org/thread.html/rb71997f506c6cc8b530dd845c084995a9878098846c7b4eacfae8db3@%3Cdev.tomcat.apache.org%3EghsaWEB
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6111nvdWEB
- www.redhat.com/archives/fedora-package-announce/2007-November/msg00525.htmlnvdWEB
- osvdb.org/34875nvd
- secunia.com/advisories/27037nvd
- secunia.com/advisories/27727nvd
- secunia.com/advisories/30802nvd
- secunia.com/advisories/30899nvd
- secunia.com/advisories/30908nvd
- secunia.com/advisories/31493nvd
- secunia.com/advisories/33668nvd
- securityreason.com/securityalert/2722nvd
- www.securityfocus.com/archive/1/469067/100/0/threadednvd
- www.securityfocus.com/archive/1/500396/100/0/threadednvd
- www.securityfocus.com/archive/1/500412/100/0/threadednvd
- www.vupen.com/english/advisories/2007/3386nvd
- www.vupen.com/english/advisories/2008/1979/referencesnvd
- www.vupen.com/english/advisories/2008/1981/referencesnvd
- www.vupen.com/english/advisories/2009/0233nvd
News mentions
0No linked articles in our index yet.