Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qpr7-5m63-hq2c

Опубликовано: 14 мая 2022
Источник: github
Github: Прошло ревью

Описание

Improper Neutralization of Input During Web Page Generation in JAMon

Multiple cross-site scripting (XSS) vulnerabilities in JAMon (Java Application Monitor) 2.7 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) listenertype or (2) currentlistener parameter to mondetail.jsp or ArraySQL parameter to (3) mondetail.jsp, (4) jamonadmin.jsp, (5) sql.jsp, or (6) exceptions.jsp.

Пакеты

Наименование

com.jamonapi:jamon

maven
Затронутые версииВерсия исправления

< 2.80

2.80

EPSS

Процентиль: 60%
0.00395
Низкий

Дефекты

CWE-79

Связанные уязвимости

ubuntu
около 12 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in JAMon (Java Application Monitor) 2.7 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) listenertype or (2) currentlistener parameter to mondetail.jsp or ArraySQL parameter to (3) mondetail.jsp, (4) jamonadmin.jsp, (5) sql.jsp, or (6) exceptions.jsp.

nvd
около 12 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in JAMon (Java Application Monitor) 2.7 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) listenertype or (2) currentlistener parameter to mondetail.jsp or ArraySQL parameter to (3) mondetail.jsp, (4) jamonadmin.jsp, (5) sql.jsp, or (6) exceptions.jsp.

debian
около 12 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in JAMon (Java App ...

EPSS

Процентиль: 60%
0.00395
Низкий

Дефекты

CWE-79