33576Third-party advisory
http://secunia.com/advisories/33576 CVE-2009-0026
Apache Jackrabbit contains Cross-site Scripting
Record summary
CVE-2009-0026 has a selected CVSS score of 4.3; EIP currently links 2 catalogued exploits.
Description
Multiple cross-site scripting (XSS) vulnerabilities in Apache Jackrabbit before 1.5.2 allow remote attackers to inject arbitrary web script or HTML via the q parameter to (1) search.jsp or (2) swr.jsp.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 2
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
org.apache.jackrabbit:jackrabbitBrowse Maven / org.apache.jackrabbit:jackrabbit | GitHub Advisory | Before 1.5.2 · Fixed in 1.5.2 | affected |
Proofs of concept
2Catalogued exploits
ExploitDBApache JackRabbit 1.4/1.5 Content Repository (JCR) - 'search.jsp?q' Cross-Site ScriptingExploitDB exploitby Red HatNot analyzed1 file
ExploitDBApache JackRabbit 1.4/1.5 Content Repository (JCR) - 'swr.jsp?q' Cross-Site ScriptingExploitDB exploitby Red HatNot analyzed1 file
References
Showing 12 of 154942Third-party advisory
http://securityreason.com/securityalert/4942 apache.orgConfirmation
http://www.apache.org/dist/jackrabbit/RELEASE-NOTES-1.5.2.txt 20090120 [ANNOUNCE] Apache Jackrabbit 1.5.2 releasedmailing list
http://www.securityfocus.com/archive/1/500196/100/0/threaded 33360vdb entry
http://www.securityfocus.com/bid/33360 ADV-2009-0177vdb entry
http://www.vupen.com/english/advisories/2009/0177 access.redhat.com
https://access.redhat.com/security/cve/CVE-2009-0026 bugzilla.redhat.com
https://bugzilla.redhat.com/show_bug.cgi?id=481126 jackrabbit-search-swr-xss(48110)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/48110 github.com
https://github.com/apache/jackrabbit/commit/36330ae8df40ceaddf9f3f95b8d4855b54921579 github.com
https://github.com/apache/jackrabbit/commit/fbdcc02bc35db1d23b527da7bc411087ef29bf1f issues.apache.orgConfirmation
https://issues.apache.org/jira/browse/JCR-1925