Vulnerability Name: | CVE-2009-3579 (CCN-53777) | ||||||||
Assigned: | 2009-10-06 | ||||||||
Published: | 2009-10-06 | ||||||||
Updated: | 2018-10-10 | ||||||||
Summary: | Cross-site scripting (XSS) vulnerability in the CookieDump.java sample application in Mort Bay Jetty 6.1.19 and 6.1.20 allows remote attackers to inject arbitrary web script or HTML via the Value parameter in a GET request to cookie/. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N) 3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-79 | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: CCN Type: BugTraq Mailing List, Tue Oct 06 2009 - 15:02:21 CDT CORE-2009-0922: Jetty Persistent XSS in Sample Cookies Application Source: MITRE Type: CNA CVE-2009-3579 Source: MISC Type: Exploit http://www.coresecurity.com/content/jetty-persistent-xss Source: CCN Type: Mort Bay Consulting Web site jetty - Jetty WebServer Source: CCN Type: OSVDB ID: 58883 Jetty CookieDump.java Sample Application cookie/ GET Request Value Parameter XSS Source: BUGTRAQ Type: UNKNOWN 20091006 CORE-2009-0922: Jetty Persistent XSS in Sample Cookies Application Source: MISC Type: UNKNOWN http://www.ush.it/team/ush/hack-jetty6x7x/jetty-adv.txt Source: XF Type: UNKNOWN jetty-cookiedump-xss(53777) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |