4.3

CVE-2009-4612

Exploit
Multiple cross-site scripting (XSS) vulnerabilities in the WebApp JSP Snoop page in Mort Bay Jetty 6.1.x through 6.1.21 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the default URI under (1) jspsnoop/, (2) jspsnoop/ERROR/, and (3) jspsnoop/IOException/, and possibly the PATH_INFO to (4) snoop.jsp.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mortbay ≫ Jetty Version 6.1.0
Mortbay ≫ Jetty Version 6.1.0 Update pre0
Mortbay ≫ Jetty Version 6.1.0 Update pre1
Mortbay ≫ Jetty Version 6.1.0 Update pre2
Mortbay ≫ Jetty Version 6.1.0 Update pre3
Mortbay ≫ Jetty Version 6.1.0 Update rc0
Mortbay ≫ Jetty Version 6.1.0 Update rc1
Mortbay ≫ Jetty Version 6.1.0 Update rc2
Mortbay ≫ Jetty Version 6.1.0 Update rc3
Mortbay ≫ Jetty Version 6.1.1
Mortbay ≫ Jetty Version 6.1.1 Update rc0
Mortbay ≫ Jetty Version 6.1.2
Mortbay ≫ Jetty Version 6.1.2 Update pre0
Mortbay ≫ Jetty Version 6.1.2 Update pre1
Mortbay ≫ Jetty Version 6.1.2 Update rc0
Mortbay ≫ Jetty Version 6.1.2 Update rc1
Mortbay ≫ Jetty Version 6.1.2 Update rc2
Mortbay ≫ Jetty Version 6.1.2 Update rc3
Mortbay ≫ Jetty Version 6.1.2 Update rc4
Mortbay ≫ Jetty Version 6.1.2 Update rc5
Mortbay ≫ Jetty Version 6.1.3
Mortbay ≫ Jetty Version 6.1.4
Mortbay ≫ Jetty Version 6.1.4 Update rc0
Mortbay ≫ Jetty Version 6.1.4 Update rc1
Mortbay ≫ Jetty Version 6.1.5
Mortbay ≫ Jetty Version 6.1.5 Update rc0
Mortbay ≫ Jetty Version 6.1.6
Mortbay ≫ Jetty Version 6.1.6 Update rc0
Mortbay ≫ Jetty Version 6.1.6 Update rc1
Mortbay ≫ Jetty Version 6.1.7
Mortbay ≫ Jetty Version 6.1.8
Mortbay ≫ Jetty Version 6.1.9
Mortbay ≫ Jetty Version 6.1.10
Mortbay ≫ Jetty Version 6.1.11
Mortbay ≫ Jetty Version 6.1.12
Mortbay ≫ Jetty Version 6.1.12 Update rc1
Mortbay ≫ Jetty Version 6.1.12 Update rc2
Mortbay ≫ Jetty Version 6.1.12 Update rc3
Mortbay ≫ Jetty Version 6.1.12 Update rc4
Mortbay ≫ Jetty Version 6.1.12 Update rc5
Mortbay ≫ Jetty Version 6.1.14
Mortbay ≫ Jetty Version 6.1.15
Mortbay ≫ Jetty Version 6.1.15 Update pre0
Mortbay ≫ Jetty Version 6.1.15 Update rc2
Mortbay ≫ Jetty Version 6.1.15 Update rc3
Mortbay ≫ Jetty Version 6.1.15 Update rc4
Mortbay ≫ Jetty Version 6.1.15 Update rc5
Mortbay ≫ Jetty Version 6.1.16
Mortbay ≫ Jetty Version 6.1.19
Mortbay ≫ Jetty Version 6.1.20
Mortbay ≫ Jetty Version 6.1.21
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.34% 0.871
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

http://www.ush.it/team/ush/hack-jetty6x7x/jetty-adv.txt
Exploit