Description
The autodeployment process in Apache Tomcat 5.5.0 through 5.5.28 and 6.0.0 through 6.0.20, when autoDeploy is enabled, deploys appBase files that remain from a failed undeploy, which might allow remote attackers to bypass intended authentication requirements via HTTP requests.
Remediation
References
Related Vulnerabilities
WordPress Plugin eHive Object Details Cross-Site Scripting (2.1.6)
Internet Information Services Other Vulnerability (CVE-2005-2678)
Oracle JRE Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2024-21140)
WordPress Plugin Polldaddy Polls & Ratings Cross-Site Scripting (2.0.31)