CVE-2008-5266
Sun Java System Application Server 9.1_01/02 Cross-Site Scripting via httpListenerEdit.jsf
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-5266. PoCs published by Eduardo Neves.
AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in Sun Glassfish by injecting a malicious script via the 'name' parameter in the URL. The payload executes arbitrary JavaScript in the context of the affected site.
Description
Cross-site scripting (XSS) vulnerability in configuration/httpListenerEdit.jsf in the GlassFish 2 UR2 b04 webadmin interface in Sun Java System Application Server 9.1_01 build b09d-fcs and 9.1_02 build b04-fcs allows remote attackers to inject arbitrary web script or HTML via the name parameter, a different vector than CVE-2008-2751.
Exploits (1)
This exploit demonstrates a cross-site scripting (XSS) vulnerability in Sun Glassfish by injecting a malicious script via the 'name' parameter in the URL. The payload executes arbitrary JavaScript in the context of the affected site.