This alert was generated using only banner information. It may be a false positive.
Fixed in Apache Tomcat 4.1.39:
moderate: Session hi-jacking CVE-2008-0128
When using the SingleSignOn Valve via https the Cookie JSESSIONIDSSO is transmitted without the "secure" attribute, resulting in it being transmitted to any content that is - by purpose or error - requested via http from the same server.
low: Cross-site scripting CVE-2008-1232
The message argument of HttpServletResponse.sendError() call is not only displayed on the error page, but is also used for the reason-phrase of HTTP response. This may include characters that are illegal in HTTP headers. It is possible for a specially crafted message to result in arbitrary content being injected into the HTTP response. For a successful XSS attack, unfiltered user supplied data must be included in the message argument.
important: Information disclosure CVE-2008-2370
When using a RequestDispatcher the target path was normalised before the query string was removed. A request that included a specially crafted request parameter could be used to access content that would otherwise be protected by a security constraint or by locating it in under the WEB-INF directory.
Affected Apache Tomcat version (4.1.0 - 4.1.37).
- moderate: Session hi-jacking CVE-2008-0128
- Upgrade Apache Tomcat to the latest version.
- WordPress Plugin Social Essentials-Social Stats and Sharing Buttons Cross-Site Scripting (1.3.1)
- WordPress Plugin Google Analyticator Multiple Cross-Site Scripting Vulnerabilities (188.8.131.52)
- WordPress Plugin Automated Editor Cross-Site Scripting (1.3)
- WordPress Plugin VaultPress Remote Code Execution (1.9.0)
- Joomla! Core 2.5.x Cross-Site Scripting (2.5.0 - 2.5.9)