← back
CVE-2010-4172

CVE-2010-4172

35Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendepss 42%
from disclosure to weapon0 days
Published on NVDNov 26
1st PoCNov 22
exploitation probability
42%top 1% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Multiple cross-site scripting (XSS) vulnerabilities in the Manager application in Apache Tomcat 6.0.12 through 6.0.29 and 7.0.0 through 7.0.4 allow remote attackers to inject arbitrary web script or HTML via the (1) orderBy or (2) sort parameter to sessionsList.jsp, or unspecified input to (3) sessionDetail.jsp or (4) java/org/apache/catalina/manager/JspHelper.java, related to use of untrusted web applications.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.