Tomcat versions 4.1.0 to 4.1.37, 5.5.0 to 5.5.26, and 6.0.0 to 6.0.16 all suffer from a cross site scripting vulnerability in HttpServletResponse.sendError().
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/68742/CVE-2008-1232.txt
Source: https://packetstormsecurity.com/files/68742/CVE-2008-1232.txt.html