Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2009-4612

Опубликовано: 13 янв. 2010
Источник: nvd
CVSS2: 4.3
EPSS Низкий

Описание

Multiple cross-site scripting (XSS) vulnerabilities in the WebApp JSP Snoop page in Mort Bay Jetty 6.1.x through 6.1.21 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the default URI under (1) jspsnoop/, (2) jspsnoop/ERROR/, and (3) jspsnoop/IOException/, and possibly the PATH_INFO to (4) snoop.jsp.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:mortbay:jetty:6.1.0:*:*:*:*:*:*:*
cpe:2.3:a:mortbay:jetty:6.1.0:pre0:*:*:*:*:*:*
cpe:2.3:a:mortbay:jetty:6.1.0:pre1:*:*:*:*:*:*
cpe:2.3:a:mortbay:jetty:6.1.0:pre2:*:*:*:*:*:*
cpe:2.3:a:mortbay:jetty:6.1.0:pre3:*:*:*:*:*:*
cpe:2.3:a:mortbay:jetty:6.1.0:rc0:*:*:*:*:*:*
cpe:2.3:a:mortbay:jetty:6.1.0:rc1:*:*:*:*:*:*
cpe:2.3:a:mortbay:jetty:6.1.0:rc2:*:*:*:*:*:*
cpe:2.3:a:mortbay:jetty:6.1.0:rc3:*:*:*:*:*:*
cpe:2.3:a:mortbay:jetty:6.1.1:*:*:*:*:*:*:*
cpe:2.3:a:mortbay:jetty:6.1.1:rc0:*:*:*:*:*:*
cpe:2.3:a:mortbay:jetty:6.1.2:*:*:*:*:*:*:*
cpe:2.3:a:mortbay:jetty:6.1.2:pre0:*:*:*:*:*:*
cpe:2.3:a:mortbay:jetty:6.1.2:pre1:*:*:*:*:*:*
cpe:2.3:a:mortbay:jetty:6.1.2:rc0:*:*:*:*:*:*
cpe:2.3:a:mortbay:jetty:6.1.2:rc1:*:*:*:*:*:*
cpe:2.3:a:mortbay:jetty:6.1.2:rc2:*:*:*:*:*:*
cpe:2.3:a:mortbay:jetty:6.1.2:rc3:*:*:*:*:*:*
cpe:2.3:a:mortbay:jetty:6.1.2:rc4:*:*:*:*:*:*
cpe:2.3:a:mortbay:jetty:6.1.2:rc5:*:*:*:*:*:*
cpe:2.3:a:mortbay:jetty:6.1.3:*:*:*:*:*:*:*
cpe:2.3:a:mortbay:jetty:6.1.4:*:*:*:*:*:*:*
cpe:2.3:a:mortbay:jetty:6.1.4:rc0:*:*:*:*:*:*
cpe:2.3:a:mortbay:jetty:6.1.4:rc1:*:*:*:*:*:*
cpe:2.3:a:mortbay:jetty:6.1.5:*:*:*:*:*:*:*
cpe:2.3:a:mortbay:jetty:6.1.5:rc0:*:*:*:*:*:*
cpe:2.3:a:mortbay:jetty:6.1.6:*:*:*:*:*:*:*
cpe:2.3:a:mortbay:jetty:6.1.6:rc0:*:*:*:*:*:*
cpe:2.3:a:mortbay:jetty:6.1.6:rc1:*:*:*:*:*:*
cpe:2.3:a:mortbay:jetty:6.1.7:*:*:*:*:*:*:*
cpe:2.3:a:mortbay:jetty:6.1.8:*:*:*:*:*:*:*
cpe:2.3:a:mortbay:jetty:6.1.9:*:*:*:*:*:*:*
cpe:2.3:a:mortbay:jetty:6.1.10:*:*:*:*:*:*:*
cpe:2.3:a:mortbay:jetty:6.1.11:*:*:*:*:*:*:*
cpe:2.3:a:mortbay:jetty:6.1.12:*:*:*:*:*:*:*
cpe:2.3:a:mortbay:jetty:6.1.12:rc1:*:*:*:*:*:*
cpe:2.3:a:mortbay:jetty:6.1.12:rc2:*:*:*:*:*:*
cpe:2.3:a:mortbay:jetty:6.1.12:rc3:*:*:*:*:*:*
cpe:2.3:a:mortbay:jetty:6.1.12:rc4:*:*:*:*:*:*
cpe:2.3:a:mortbay:jetty:6.1.12:rc5:*:*:*:*:*:*
cpe:2.3:a:mortbay:jetty:6.1.14:*:*:*:*:*:*:*
cpe:2.3:a:mortbay:jetty:6.1.15:*:*:*:*:*:*:*
cpe:2.3:a:mortbay:jetty:6.1.15:pre0:*:*:*:*:*:*
cpe:2.3:a:mortbay:jetty:6.1.15:rc2:*:*:*:*:*:*
cpe:2.3:a:mortbay:jetty:6.1.15:rc3:*:*:*:*:*:*
cpe:2.3:a:mortbay:jetty:6.1.15:rc4:*:*:*:*:*:*
cpe:2.3:a:mortbay:jetty:6.1.15:rc5:*:*:*:*:*:*
cpe:2.3:a:mortbay:jetty:6.1.16:*:*:*:*:*:*:*
cpe:2.3:a:mortbay:jetty:6.1.19:*:*:*:*:*:*:*
cpe:2.3:a:mortbay:jetty:6.1.20:*:*:*:*:*:*:*
cpe:2.3:a:mortbay:jetty:6.1.21:*:*:*:*:*:*:*

EPSS

Процентиль: 33%
0.0013
Низкий

4.3 Medium

CVSS2

Дефекты

CWE-79

Связанные уязвимости

ubuntu
почти 16 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the WebApp JSP Snoop page in Mort Bay Jetty 6.1.x through 6.1.21 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the default URI under (1) jspsnoop/, (2) jspsnoop/ERROR/, and (3) jspsnoop/IOException/, and possibly the PATH_INFO to (4) snoop.jsp.

redhat
около 16 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the WebApp JSP Snoop page in Mort Bay Jetty 6.1.x through 6.1.21 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the default URI under (1) jspsnoop/, (2) jspsnoop/ERROR/, and (3) jspsnoop/IOException/, and possibly the PATH_INFO to (4) snoop.jsp.

debian
почти 16 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the WebApp JSP ...

github
больше 3 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the WebApp JSP Snoop page in Mort Bay Jetty 6.1.x through 6.1.21 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the default URI under (1) jspsnoop/, (2) jspsnoop/ERROR/, and (3) jspsnoop/IOException/, and possibly the PATH_INFO to (4) snoop.jsp.

EPSS

Процентиль: 33%
0.0013
Низкий

4.3 Medium

CVSS2

Дефекты

CWE-79