Description
Multiple cross-site scripting (XSS) vulnerabilities in certain JSP files in the examples web application in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.36, 5.0.0 through 5.0.30, 5.5.0 through 5.5.24, and 6.0.0 through 6.0.13 allow remote attackers to inject arbitrary web script or HTML via the portion of the URI after the ';' character, as demonstrated by a URI containing a "snp/snoop.jsp;" sequence.
Remediation
References
Related Vulnerabilities
WordPress Plugin XML Sitemap & Google News feeds Cross-Site Scripting (4.5)
WordPress Plugin Local Market Explorer 'api-key' Parameter Cross-Site Scripting (3.1.1)
WordPress Plugin WP Fastest Cache Cross-Site Request Forgery (0.9.0.2)
MySQL CVE-2014-6551 Vulnerability (CVE-2014-6551)
WordPress Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2007-4893)