The Tomcat Host Manager web application does not escape user provided data before including it in the output.

http://www.securiteam.com/unixfocus/5TP0215OKS.html