CVE-2007-1358
Apache Tomcat XSS In Accept-Language Headers
EPSS 44.2%
Description
Cross-site scripting (XSS) vulnerability in certain applications using Apache Tomcat 4.0.0 through 4.0.6 and 4.1.0 through 4.1.34 allows remote attackers to inject arbitrary web script or HTML via crafted "Accept-Language headers that do not conform to RFC 2616".
How to fix CVE-2007-1358
No fixed version has been published yet. Mitigate by removing the affected package or applying upstream guidance from the references below.
- Maven/org.apache.tomcat:tomcat—no fix listed
Is CVE-2007-1358 being exploited?
Moderate — EPSS is 44.2%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (1)
- >= 4.0.0, <= 4.0.6