Record summary

CVE-2009-0026 has a selected CVSS score of 4.3; EIP currently links 2 catalogued exploits.

Description

Multiple cross-site scripting (XSS) vulnerabilities in Apache Jackrabbit before 1.5.2 allow remote attackers to inject arbitrary web script or HTML via the q parameter to (1) search.jsp or (2) swr.jsp.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
2

Affected products and versions

1
ProductSourceVersion rangeStatus

org.apache.jackrabbit:jackrabbit

Browse Maven / org.apache.jackrabbit:jackrabbit
GitHub AdvisoryBefore 1.5.2 · Fixed in 1.5.2affected

Proofs of concept

2

Catalogued exploits

ExploitDBApache JackRabbit 1.4/1.5 Content Repository (JCR) - 'search.jsp?q' Cross-Site ScriptingExploitDB exploitby Red HatNot analyzed1 file
ExploitDB

PoC details
ExploitDBApache JackRabbit 1.4/1.5 Content Repository (JCR) - 'swr.jsp?q' Cross-Site ScriptingExploitDB exploitby Red HatNot analyzed1 file
ExploitDB

PoC details

References

Showing 12 of 15