<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 09:28:22 +0000</lastBuildDate>
    <item>
      <title>certa-2007-avi-362 — Plusieurs vulnérabilités du moteur de &lt;span
class="textit"&gt;servlets&lt;/span&gt; &lt;span class="textit"&gt;Tomcat&lt;/span&gt;
permetten…</title>
      <link>https://cve.radiocsirt.org/vuln/certa-2007-avi-362</link>
      <description>certa-2007-avi-362</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certa-2007-avi-362</guid>
    </item>
    <item>
      <title>EUVD-2026-135342</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-135342</link>
      <description>EUVD-2026-135342</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-135342</guid>
    </item>
    <item>
      <title>fkie_cve-2007-3386</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2007-3386</link>
      <description>&lt;p&gt;Cross-site scripting (XSS) vulnerability in the Host Manager Servlet for Apache Tomcat 6.0.0 to 6.0.13 and 5.5.0 to 5.5.24 allows remote attackers to inject arbitrary HTML and web script via crafted requests, as demonstrated using the aliases parameter to an html/add action.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Cross-site scripting (XSS) vulnerability in the Host Manager Servlet for Apache Tomcat 6.0.0 to 6.0.13 and 5.5.0 to 5.5.24 allows remote attackers to inject arbitrary HTML and web script via crafted requests, as demonstrated using the aliases parameter to an html/add action.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2007-3386</guid>
    </item>
    <item>
      <title>GHSA-v66v-63h2-8q5q</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-v66v-63h2-8q5q</link>
      <description>&lt;p&gt;Cross-site scripting (XSS) vulnerability in the Host Manager Servlet for Apache Tomcat 6.0.0 to 6.0.13 and 5.5.0 to 5.5.24 allows remote attackers to inject arbitrary HTML and web script via crafted requests, as demonstrated using the aliases parameter to an html/add action.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Cross-site scripting (XSS) vulnerability in the Host Manager Servlet for Apache Tomcat 6.0.0 to 6.0.13 and 5.5.0 to 5.5.24 allows remote attackers to inject arbitrary HTML and web script via crafted requests, as demonstrated using the aliases parameter to an html/add action.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-v66v-63h2-8q5q</guid>
    </item>
    <item>
      <title>gsd-2007-3386</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2007-3386</link>
      <description>gsd-2007-3386</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2007-3386</guid>
    </item>
    <item>
      <title>jvndb-2007-000598</title>
      <link>https://cve.radiocsirt.org/vuln/jvndb-2007-000598</link>
      <description>&lt;p&gt;Apache Tomcat, from the Apache Software Foundation, contains a cross-site scripting vulnerability.&#13;
&#13;
Apache Tomcat from the Apache Software Foundation is an implementation of the Java Servlet and JavaServer Page (JSP) technologies.&#13;
&#13;
The Host Manager Servlet does not properly filter user supplied data. This enables an cross-site scripting attack.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Apache Tomcat, from the Apache Software Foundation, contains a cross-site scripting vulnerability.&#13;
&#13;
Apache Tomcat from the Apache Software Foundation is an implementation of the Java Servlet and JavaServer Page (JSP) technologies.&#13;
&#13;
The Host Manager Servlet does not properly filter user supplied data. This enables an cross-site scripting attack.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/jvndb-2007-000598</guid>
    </item>
    <item>
      <title>RHSA-2007:0871 — Red Hat Security Advisory: tomcat security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2007:0871</link>
      <description>&lt;p&gt;tomcat handling of cookies tomcat handling of cookie values tomcat host manager xss&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;tomcat handling of cookies tomcat handling of cookie values tomcat host manager xss&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2007:0871</guid>
    </item>
  </channel>
</rss>
