A cross-site scripting vulnerability, tracked as CVE-2007-3386, affects the Host Manager Servlet in Apache Tomcat versions 6.0.0 through 6.0.13 and 5.5.0 through 5.5.24. A remote attacker can submit crafted requests to inject arbitrary HTML or browser-executed script into Host Manager responses.
The flaw can be triggered through the aliases parameter used by the Host Manager html/add action. Organizations operating affected Tomcat deployments should update to a version that remediates the issue and restrict access to the Host Manager interface, particularly where it may be reachable by untrusted users.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
The CVE record for CVE-2007-3386 was updated.
CVE-2007-3386 was published for a cross-site scripting vulnerability in Apache Tomcat's Host Manager Servlet. The flaw affects Tomcat 6.0.0 through 6.0.13 and 5.5.0 through 5.5.24, and crafted requests using the html/add action's aliases parameter can inject arbitrary HTML and script.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.