<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 21:25:06 +0000</lastBuildDate>
    <item>
      <title>certa-2007-avi-267 — Une vulnérabilité dans les applications d'administration de &lt;span
class="textit"&gt;Tomcat&lt;/span&gt; et dans des exemples d'a…</title>
      <link>https://cve.radiocsirt.org/vuln/certa-2007-avi-267</link>
      <description>certa-2007-avi-267</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certa-2007-avi-267</guid>
    </item>
    <item>
      <title>EUVD-2026-134481</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-134481</link>
      <description>EUVD-2026-134481</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-134481</guid>
    </item>
    <item>
      <title>fkie_cve-2007-2449</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2007-2449</link>
      <description>&lt;p&gt;Multiple cross-site scripting (XSS) vulnerabilities in certain JSP files in the examples web application in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.36, 5.0.0 through 5.0.30, 5.5.0 through 5.5.24, and 6.0.0 through 6.0.13 allow remote attackers to inject arbitrary web script or HTML via the portion of the URI after the &amp;#39;;&amp;#39; character, as demonstrated by a URI containing a &amp;#34;snp/snoop.jsp;&amp;#34; sequence.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Multiple cross-site scripting (XSS) vulnerabilities in certain JSP files in the examples web application in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.36, 5.0.0 through 5.0.30, 5.5.0 through 5.5.24, and 6.0.0 through 6.0.13 allow remote attackers to inject arbitrary web script or HTML via the portion of the URI after the &amp;#39;;&amp;#39; character, as demonstrated by a URI containing a &amp;#34;snp/snoop.jsp;&amp;#34; sequence.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2007-2449</guid>
    </item>
    <item>
      <title>GHSA-hc39-rjwp-qffq — Apache Tomcat XSS Vulnerabilities in Examples Web Application</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-hc39-rjwp-qffq</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.tomcat:tomcat&lt;/p&gt;
&lt;p&gt;Multiple cross-site scripting (XSS) vulnerabilities in certain JSP files in the examples web application in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.36, 5.0.0 through 5.0.30, 5.5.0 through 5.5.24, and 6.0.0 through 6.0.13 allow remote attackers to inject arbitrary web script or HTML via the portion of the URI after the `;` character, as demonstrated by a URI containing a `snp/snoop.jsp;` sequence.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.tomcat:tomcat&lt;/p&gt;
&lt;p&gt;Multiple cross-site scripting (XSS) vulnerabilities in certain JSP files in the examples web application in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.36, 5.0.0 through 5.0.30, 5.5.0 through 5.5.24, and 6.0.0 through 6.0.13 allow remote attackers to inject arbitrary web script or HTML via the portion of the URI after the `;` character, as demonstrated by a URI containing a `snp/snoop.jsp;` sequence.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-hc39-rjwp-qffq</guid>
    </item>
    <item>
      <title>gsd-2007-2449</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2007-2449</link>
      <description>gsd-2007-2449</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2007-2449</guid>
    </item>
    <item>
      <title>jvndb-2007-000456</title>
      <link>https://cve.radiocsirt.org/vuln/jvndb-2007-000456</link>
      <description>&lt;p&gt;Apache Tomcat, from the Apache Software Foundation, contains a cross-site scripting vulnerability in its sample program.&#13;
&#13;
Apache Tomcat from the Apache Software Foundation is an implementation of the Java Servlet and JavaServer Page (JSP) technologies.&#13;
&#13;
jsp-examples, a sample web application included in Apache Tomcat, contains a cross-site scripting vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Apache Tomcat, from the Apache Software Foundation, contains a cross-site scripting vulnerability in its sample program.&#13;
&#13;
Apache Tomcat from the Apache Software Foundation is an implementation of the Java Servlet and JavaServer Page (JSP) technologies.&#13;
&#13;
jsp-examples, a sample web application included in Apache Tomcat, contains a cross-site scripting vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/jvndb-2007-000456</guid>
    </item>
    <item>
      <title>RHSA-2007:0569 — Red Hat Security Advisory: tomcat security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2007:0569</link>
      <description>&lt;p&gt;tomcat examples jsp XSS tomcat host manager XSS&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;tomcat examples jsp XSS tomcat host manager XSS&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2007:0569</guid>
    </item>
  </channel>
</rss>
