Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2009-1554

Опубликовано: 06 мая 2009
Источник: nvd
CVSS2: 4.3
EPSS Низкий

Описание

Cross-site scripting (XSS) vulnerability in ThemeServlet.java in Sun Woodstock 4.2, as used in Sun GlassFish Enterprise Server and other products, allows remote attackers to inject arbitrary web script or HTML via a UTF-7 string in the PATH_INFO, which is displayed on the 404 error page, as demonstrated by the PATH_INFO to theme/META-INF.

Уязвимые конфигурации

Конфигурация 1

Одновременно

Одно из

cpe:2.3:a:oracle:glassfish_server:1.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:glassfish_server:1.0:ur1:*:*:*:*:*:*
cpe:2.3:a:oracle:glassfish_server:1.0:ur1_po1:*:*:*:*:*:*
cpe:2.3:a:oracle:glassfish_server:2.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:glassfish_server:2.1:*:*:*:*:*:*:*
cpe:2.3:a:oracle:glassfish_server:2.1.1:*:*:*:*:*:*:*
cpe:2.3:a:oracle:glassfish_server:3.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:glassfish_server:3.0.1:*:*:*:*:*:*:*
cpe:2.3:a:sun:woodstock:4.2:*:*:*:*:*:*:*

EPSS

Процентиль: 81%
0.01556
Низкий

4.3 Medium

CVSS2

Дефекты

CWE-79

Связанные уязвимости

github
почти 4 года назад

Cross-site scripting (XSS) vulnerability in ThemeServlet.java in Sun Woodstock 4.2, as used in Sun GlassFish Enterprise Server and other products, allows remote attackers to inject arbitrary web script or HTML via a UTF-7 string in the PATH_INFO, which is displayed on the 404 error page, as demonstrated by the PATH_INFO to theme/META-INF.

EPSS

Процентиль: 81%
0.01556
Низкий

4.3 Medium

CVSS2

Дефекты

CWE-79