Vulnerability record · CVE-2007-1355 · published 21 May 2007
CVE-2007-1355: Apache Tomcat sample hello.jsp XSS via test parameter
Apache · Tomcat
The bundled example application appdev/sample/web/hello.jsp in Apache Tomcat reflects the test parameter and other unspecified inputs without proper output encoding, allowing cross-site scripting. Because the vulnerable file ships with the sample web application, any deployment that leaves the examples installed exposes users to script injection in their browsers.
Description
Multiple cross-site scripting (XSS) vulnerabilities in the appdev/sample/web/hello.jsp example application in Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.36, 5.0.0 through 5.0.30, 5.5.0 through 5.5.23, and 6.0.0 through 6.0.10 allow remote attackers to inject arbitrary web script or HTML via the test parameter and unspecified vectors.
AV:N/AC:M/Au:N/C:N/I:P/A:N
Automated analysis
medium priorityThe flaw is a reflected XSS in a sample application with public exploit code and high EPSS, but it only affects hosts where the examples are deployed and has limited CVSS impact.
What it is
The bundled example application appdev/sample/web/hello.jsp in Apache Tomcat reflects the test parameter and other unspecified inputs without proper output encoding, allowing cross-site scripting. Because the vulnerable file ships with the sample web application, any deployment that leaves the examples installed exposes users to script injection in their browsers.
Impact
An attacker can execute arbitrary script or HTML in the context of a victim's session on the affected Tomcat host, enabling session theft, credential phishing, or page defacement. The CVSS vector shows partial integrity impact only, with no confidentiality or availability impact.
Attack surface
Reachable over the network via HTTP requests to the sample hello.jsp page, with no authentication required. Exploitation requires the victim to load a crafted link or submit crafted input, so some user interaction is needed.
Exploitation
CISA KEV does not list this CVE, but EPSS is high at roughly 0.58 (99th percentile), and a SecurityFocus reference is tagged Exploit and Patch, indicating public exploit code exists.
What to do
- Upgrade Tomcat to a release later than the affected 4.0.x, 4.1.x, 5.0.x, 5.5.x, and 6.0.x ranges listed in the advisory.
- Remove or disable the bundled sample and example web applications, including appdev/sample, from production servers.
- Apply vendor errata from Red Hat, Apple, Sun, and CA where Tomcat is packaged or embedded.
- If examples must remain, add output encoding or input validation for the test parameter and other reflected inputs.
- Restrict network access to example applications to trusted administrative networks.
Detection
- Search web access logs for requests to appdev/sample/web/hello.jsp containing script tags or encoded script in the test parameter.
- Alert on any HTTP traffic to sample or example application paths on production Tomcat instances.
- Review deployed Tomcat webapps directories for the presence of the appdev/sample application.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2007-1355 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2007-1355), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.