Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2013-1880

Опубликовано: 21 мар. 2013
Источник: redhat
CVSS2: 4.3

Описание

Cross-site scripting (XSS) vulnerability in the Portfolio publisher servlet in the demo web application in Apache ActiveMQ before 5.9.0 allows remote attackers to inject arbitrary web script or HTML via the refresh parameter to demo/portfolioPublish, a different vulnerability than CVE-2012-6092.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Enterprise 1activemqNot affected
Red Hat JBoss Enterprise Web Server 1fusesourceAffected
Fuse MQ Enterprise 7.1.0FixedRHSA-2013:102909.07.2013

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=924447ActiveMQ: XSS vulnerability in portfolioPublish demo application

4.3 Medium

CVSS2

Связанные уязвимости

ubuntu
около 12 лет назад

Cross-site scripting (XSS) vulnerability in the Portfolio publisher servlet in the demo web application in Apache ActiveMQ before 5.9.0 allows remote attackers to inject arbitrary web script or HTML via the refresh parameter to demo/portfolioPublish, a different vulnerability than CVE-2012-6092.

nvd
около 12 лет назад

Cross-site scripting (XSS) vulnerability in the Portfolio publisher servlet in the demo web application in Apache ActiveMQ before 5.9.0 allows remote attackers to inject arbitrary web script or HTML via the refresh parameter to demo/portfolioPublish, a different vulnerability than CVE-2012-6092.

debian
около 12 лет назад

Cross-site scripting (XSS) vulnerability in the Portfolio publisher se ...

github
больше 3 лет назад

Apache ActiveMQ Cross-site scripting (XSS) vulnerability in the Portfolio publisher servlet

4.3 Medium

CVSS2