Language:
https://markmail.org/thread/wfu4nff5chvkb6xp
http://svn.apache.org/viewvc?view=revision&revision=834047
http://www.nessus.org/u?e7339edb
Severity: Critical
ID: 34970
File Name: tomcat_manager_common_creds.nasl
Version: 1.39
Type: remote
Family: Web Servers
Published: 11/26/2008
Updated: 11/15/2018
Supported Sensors: Nessus
Risk Factor: High
Score: 7.3
Risk Factor: Critical
Base Score: 10
Temporal Score: 8.3
Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C
Risk Factor: Critical
Base Score: 9.8
Temporal Score: 9.1
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Temporal Vector: CVSS:3.0/E:F/RL:O/RC:C
CPE: cpe:/a:apache:tomcat
Required KB Items: installed_sw/Apache Tomcat
Excluded KB Items: global_settings/supplied_logins_only
Exploit Available: true
Exploit Ease: Exploits are available
Exploited by Nessus: true
Patch Publication Date: 11/9/2009
Core Impact
Metasploit (Apache Tomcat Manager Authenticated Upload Code Execution)
CVE: CVE-2009-3099, CVE-2009-3548, CVE-2010-0557, CVE-2010-4094
BID: 36253, 36954, 37086, 38084, 44172
CWE: 255
ZDI: ZDI-10-214