Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.56128
Category:Red Hat Local Security Checks
Title:RedHat Security Advisory RHSA-2006:0157
Summary:NOSUMMARY
Description:Description:

The remote host is missing updates announced in
advisory RHSA-2006:0157.

Red Hat Application Server packages provide a J2EE Application Server and
Web container as well as the underlying Java stack.

A cross-site scripting flaw was found in the way Struts displays error
pages. It may be possible for an attacker to construct a specially crafted
URL which could fool a victim into believing they are viewing a trusted
site. The Common Vulnerabilities and Exposures project assigned the
name CVE-2005-3745 to this issue. Please note that this issue does not
affect Struts running on Tomcat or JOnAS, which is our supported usage of
Struts.

All users of Red Hat Application Server should upgrade to these updated
packages, which contain Struts version 1.2.8 which is not vulnerable to
this issue.

Solution:
Please note that this update is available via
Red Hat Network. To use Red Hat Network, launch the Red
Hat Update Agent with the following command: up2date

http://rhn.redhat.com/errata/RHSA-2006-0157.html

Risk factor : Medium

CVSS Score:
4.3

Cross-Ref: BugTraq ID: 15512
Common Vulnerability Exposure (CVE) ID: CVE-2005-3745
http://www.securityfocus.com/bid/15512
Bugtraq: 20051121 Security Advisory: Struts Error Message Cross Site Scripting (Google Search)
http://www.securityfocus.com/archive/1/417296/30/0/threaded
http://www.hacktics.com/AdvStrutsNov05.html
https://lists.apache.org/thread.html/r02c2d634fa74209d941c90f9a4cd36a6f12366ca65f9b90446ff2de3@%3Cissues.struts.apache.org%3E
https://lists.apache.org/thread.html/rf482c101a88445d73cc2e89dbf7f16ae00a4aa79a544a1e72b2326db@%3Cissues.struts.apache.org%3E
http://www.osvdb.org/21021
http://www.redhat.com/support/errata/RHSA-2006-0157.html
http://www.redhat.com/support/errata/RHSA-2006-0161.html
http://securitytracker.com/id?1015257
http://secunia.com/advisories/17677
http://secunia.com/advisories/18341
http://securityreason.com/securityalert/197
http://www.vupen.com/english/advisories/2005/2525
CopyrightCopyright (c) 2006 E-Soft Inc. http://www.securityspace.com

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.