S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2007-2449 Scanner

Detects 'Cross-Site Scripting (XSS)' vulnerability in Apache Tomcat affects v. 4.0.0 through 4.0.6, 4.1.0 through 4.1.36, 5.0.0 through 5.0.30, 5.5.0 through 5.5.24, and 6.0.0 through 6.0.13.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.5k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2007-2449
4.3
CVSS

Multiple cross-site scripting (XSS) vulnerabilities in certain JSP files in the examples web application in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.36, 5.0.0 through 5.0.30, 5.5.0 through 5.5.24, and 6.0.0 through 6.0.13 allow remote attackers to inject arbitrary web script or HTML via the portion of the URI after the ';' character, as demonstrated by a URI containing a "snp/snoop.jsp;" sequence.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

Apache Tomcat is a popular open-source web server and servlet container used for deploying Java-based web applications. It is widely used by developers and organizations to build and deploy Java applications on the web. Apache Tomcat provides a flexible and powerful platform for serving web content and managing Java applications.

CVE-2007-2449 is a cross-site scripting vulnerability that was detected in Apache Tomcat versions 4.0.0 through 6.0.13. This vulnerability allowed remote attackers to inject arbitrary web script or HTML via the URI after the ';' character. It was demonstrated that a URI containing a "snp/snoop.jsp;" sequence could exploit the vulnerability.

When exploited, this vulnerability can lead to a range of malicious activities, including stealing sensitive data, session hijacking, and unauthorized access to server resources. Attackers can exploit this vulnerability to inject malicious scripts into a web page, allowing them to steal user credentials or spread malware to unsuspecting users.

Those who read this article can easily and quickly learn about vulnerabilities in their digital assets by using the pro features of the s4e.io platform. With advanced scanning capabilities and actionable insights, this platform can help users identify and mitigate vulnerabilities in their web applications and servers, ensuring the security and integrity of their digital assets.

 

REFERENCES

Solution Advice

To protect against this vulnerability, users are recommended to take the following precautions:

  • Upgrade to the latest version of Apache Tomcat, which has been patched to address this vulnerability
  • Disable unnecessary JSP files or restrict access to them
  • Implement input validation and sanitation to prevent the injection of malicious scripts or HTML
  • Use a web application firewall or intrusion detection system to detect and block exploit attempts
  • Conduct regular security audits and vulnerability scans to identify and remediate potential vulnerabilities

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2007-2449 scanner - Cross-Site Scripting (XSS) vulnerability in Apache Tomcat | S4E