7.5

CVE-2009-4611

Exploit
Mort Bay Jetty 6.x through 6.1.22 and 7.0.0 writes backtrace data without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwrite files, via an HTTP request containing an escape sequence for a terminal emulator, related to (1) a string value in the Age parameter to the default URI for the Cookie Dump Servlet in test-jetty-webapp/src/main/java/com/acme/CookieDump.java under cookie/, (2) an alphabetic value in the A parameter to jsp/expr.jsp, or (3) an alphabetic value in the Content-Length HTTP header to an arbitrary application.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mortbay ≫ Jetty Version 6.0.0
Mortbay ≫ Jetty Version 6.0.0 Update alpha0
Mortbay ≫ Jetty Version 6.0.0 Update alpha1
Mortbay ≫ Jetty Version 6.0.0 Update alpha2
Mortbay ≫ Jetty Version 6.0.0 Update alpha3
Mortbay ≫ Jetty Version 6.0.0 Update beta0
Mortbay ≫ Jetty Version 6.0.0 Update beta1
Mortbay ≫ Jetty Version 6.0.0 Update beta10
Mortbay ≫ Jetty Version 6.0.0 Update beta11
Mortbay ≫ Jetty Version 6.0.0 Update beta12
Mortbay ≫ Jetty Version 6.0.0 Update beta14
Mortbay ≫ Jetty Version 6.0.0 Update beta15
Mortbay ≫ Jetty Version 6.0.0 Update beta16
Mortbay ≫ Jetty Version 6.0.0 Update beta17
Mortbay ≫ Jetty Version 6.0.0 Update beta2
Mortbay ≫ Jetty Version 6.0.0 Update beta3
Mortbay ≫ Jetty Version 6.0.0 Update beta4
Mortbay ≫ Jetty Version 6.0.0 Update beta5
Mortbay ≫ Jetty Version 6.0.0 Update beta6
Mortbay ≫ Jetty Version 6.0.0 Update beta7
Mortbay ≫ Jetty Version 6.0.0 Update beta8
Mortbay ≫ Jetty Version 6.0.0 Update beta9
Mortbay ≫ Jetty Version 6.0.0 Update betax
Mortbay ≫ Jetty Version 6.0.0 Update rc0
Mortbay ≫ Jetty Version 6.0.0 Update rc1
Mortbay ≫ Jetty Version 6.0.0 Update rc2
Mortbay ≫ Jetty Version 6.0.0 Update rc3
Mortbay ≫ Jetty Version 6.0.0 Update rc4
Mortbay ≫ Jetty Version 6.0.1
Mortbay ≫ Jetty Version 6.0.2
Mortbay ≫ Jetty Version 6.1.0
Mortbay ≫ Jetty Version 6.1.0 Update pre0
Mortbay ≫ Jetty Version 6.1.0 Update pre1
Mortbay ≫ Jetty Version 6.1.0 Update pre2
Mortbay ≫ Jetty Version 6.1.0 Update pre3
Mortbay ≫ Jetty Version 6.1.0 Update rc0
Mortbay ≫ Jetty Version 6.1.0 Update rc1
Mortbay ≫ Jetty Version 6.1.0 Update rc2
Mortbay ≫ Jetty Version 6.1.0 Update rc3
Mortbay ≫ Jetty Version 6.1.1
Mortbay ≫ Jetty Version 6.1.1 Update rc0
Mortbay ≫ Jetty Version 6.1.2
Mortbay ≫ Jetty Version 6.1.2 Update pre0
Mortbay ≫ Jetty Version 6.1.2 Update pre1
Mortbay ≫ Jetty Version 6.1.2 Update rc0
Mortbay ≫ Jetty Version 6.1.2 Update rc1
Mortbay ≫ Jetty Version 6.1.2 Update rc2
Mortbay ≫ Jetty Version 6.1.2 Update rc3
Mortbay ≫ Jetty Version 6.1.2 Update rc4
Mortbay ≫ Jetty Version 6.1.2 Update rc5
Mortbay ≫ Jetty Version 6.1.3
Mortbay ≫ Jetty Version 6.1.4
Mortbay ≫ Jetty Version 6.1.4 Update rc0
Mortbay ≫ Jetty Version 6.1.4 Update rc1
Mortbay ≫ Jetty Version 6.1.5
Mortbay ≫ Jetty Version 6.1.5 Update rc0
Mortbay ≫ Jetty Version 6.1.6
Mortbay ≫ Jetty Version 6.1.6 Update rc0
Mortbay ≫ Jetty Version 6.1.6 Update rc1
Mortbay ≫ Jetty Version 6.1.7
Mortbay ≫ Jetty Version 6.1.8
Mortbay ≫ Jetty Version 6.1.9
Mortbay ≫ Jetty Version 6.1.10
Mortbay ≫ Jetty Version 6.1.11
Mortbay ≫ Jetty Version 6.1.12
Mortbay ≫ Jetty Version 6.1.12 Update rc1
Mortbay ≫ Jetty Version 6.1.12 Update rc2
Mortbay ≫ Jetty Version 6.1.12 Update rc3
Mortbay ≫ Jetty Version 6.1.12 Update rc4
Mortbay ≫ Jetty Version 6.1.12 Update rc5
Mortbay ≫ Jetty Version 6.1.14
Mortbay ≫ Jetty Version 6.1.15
Mortbay ≫ Jetty Version 6.1.15 Update pre0
Mortbay ≫ Jetty Version 6.1.15 Update rc2
Mortbay ≫ Jetty Version 6.1.15 Update rc3
Mortbay ≫ Jetty Version 6.1.15 Update rc4
Mortbay ≫ Jetty Version 6.1.15 Update rc5
Mortbay ≫ Jetty Version 6.1.16
Mortbay ≫ Jetty Version 6.1.19
Mortbay ≫ Jetty Version 6.1.20
Mortbay ≫ Jetty Version 7.0.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.18% 0.864
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://www.ush.it/team/ush/hack-jetty6x7x/jetty-adv.txt
Exploit
http://www.securityfocus.com/archive/1/508830/100/0/threaded
http://www.ush.it/team/ush/hack_httpd_escape/adv.txt
Exploit