Описание
A cross-site scripting vulnerability in Caucho Technology Resin before 1.2.4 allows a malicious webmaster to embed Javascript in a hyperlink that ends in a .jsp extension, which causes an error message that does not properly quote the Javascript.
Ссылки
- Vendor Advisory
- US Government Resource
- ExploitPatchVendor Advisory
- Vendor Advisory
- US Government Resource
- ExploitPatchVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.2.4 (включая)
Одно из
cpe:2.3:a:caucho_technology:resin:*:*:*:*:*:*:*:*
cpe:2.3:a:caucho_technology:resin:1.2.2:*:*:*:*:*:*:*
EPSS
Процентиль: 72%
0.00706
Низкий
5.1 Medium
CVSS2
Дефекты
NVD-CWE-Other
Связанные уязвимости
github
почти 4 года назад
A cross-site scripting vulnerability in Caucho Technology Resin before 1.2.4 allows a malicious webmaster to embed Javascript in a hyperlink that ends in a .jsp extension, which causes an error message that does not properly quote the Javascript.
EPSS
Процентиль: 72%
0.00706
Низкий
5.1 Medium
CVSS2
Дефекты
NVD-CWE-Other