DO NOT REPLY [Bug 42950] New: - ConcurrentModificationException on Shutdown

2007-07-21 Thread bugzilla
DO NOT REPLY TO THIS EMAIL, BUT PLEASE POST YOUR BUGĀ· RELATED COMMENTS THROUGH THE WEB INTERFACE AVAILABLE AT . ANY REPLY MADE TO THIS MESSAGE WILL NOT BE COLLECTED ANDĀ· INSERTED IN THE BUG DATABASE. http://issues.apache.org/bugzilla/show_bu

svn commit: r558396 - in /tomcat/site/trunk: docs/security-4.html xdocs/security-4.xml

2007-07-21 Thread markt
Author: markt Date: Sat Jul 21 16:49:16 2007 New Revision: 558396 URL: http://svn.apache.org/viewvc?view=rev&rev=558396 Log: Add information for CVE-2007-3383 Modified: tomcat/site/trunk/docs/security-4.html tomcat/site/trunk/xdocs/security-4.xml Modified: tomcat/site/trunk/docs/security

CVE-2007-3383: XSS in Tomcat send mail example

2007-07-21 Thread Mark Thomas
CVE-2007-3383: XSS in Tomcat send mail example Severity: Low (Cross-site scripting) Vendor: The Apache Software Foundation Versions Affected: 4.0.0 to 4.0.6 4.1.0 to 4.1.36 Description: When reporting error messages, the SendMailServlet does not filter user supplied data before display. This en