| Multiple cross-site scripting (XSS) vulnerabilities in the (1) Manager
and (2) Host Manager web applications in Apache Tomcat 4.0.0 through
4.0.6, 4.1.0 through 4.1.36, 5.0.0 through 5.0.30, 5.5.0 through
5.5.24, and 6.0.0 through 6.0.13 allow remote authenticated users to
inject arbitrary web script or HTML via a parameter name to
manager/html/upload, and other unspecified vectors.
|