CVE-2009-1553
GlassFish Enterprise Server 2.1 - Stored Cross-Site Scripting via Admin Console Query Parameters
Title source: llmExploitation Summary
EIP tracks 8 public exploits for CVE-2009-1553. PoCs published by DSecRG.
AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in GlassFish Enterprise Server 2.1 by injecting malicious JavaScript code via unsanitized user input in the URL. The payload triggers an alert dialog, confirming the vulnerability.
Description
Multiple cross-site scripting (XSS) vulnerabilities in the Admin Console in Sun GlassFish Enterprise Server 2.1 allow remote attackers to inject arbitrary web script or HTML via the query string to (1) applications/applications.jsf, (2) configuration/configuration.jsf, (3) customMBeans/customMBeans.jsf, (4) resourceNode/resources.jsf, (5) sysnet/registration.jsf, or (6) webService/webServicesGeneral.jsf; or the name parameter to (7) configuration/auditModuleEdit.jsf, (8) configuration/httpListenerEdit.jsf, or (9) resourceNode/jdbcResourceEdit.jsf.
Exploits (8)
This exploit demonstrates a cross-site scripting (XSS) vulnerability in GlassFish Enterprise Server 2.1 by injecting malicious JavaScript code via unsanitized user input in the URL. The payload triggers an alert dialog, confirming the vulnerability.
This exploit demonstrates a cross-site scripting (XSS) vulnerability in GlassFish Enterprise Server 2.1 by injecting malicious JavaScript code via an unsanitized input parameter in the URL. The PoC triggers an alert dialog, proving arbitrary script execution in the context of the affected site.
This exploit demonstrates a cross-site scripting (XSS) vulnerability in GlassFish Enterprise Server 2.1 by injecting malicious JavaScript code via an unsanitized input parameter in the URL. The payload executes an alert dialog, proving arbitrary script execution in the context of the affected site.
This exploit demonstrates a cross-site scripting (XSS) vulnerability in GlassFish Enterprise Server 2.1 by injecting malicious JavaScript code via the URL parameter. The payload executes an alert dialog, confirming the vulnerability.
This exploit demonstrates a cross-site scripting (XSS) vulnerability in GlassFish Enterprise Server 2.1 by injecting malicious JavaScript code via the URL parameter. The payload triggers an alert dialog, proving arbitrary script execution in the context of the affected site.
This exploit demonstrates a cross-site scripting (XSS) vulnerability in GlassFish Enterprise Server 2.1 by injecting malicious JavaScript code via the URL parameter. The payload executes an alert dialog, proving arbitrary script execution in the context of the affected site.
This exploit demonstrates a cross-site scripting (XSS) vulnerability in GlassFish Enterprise Server 2.1 by injecting malicious JavaScript code via the 'name' parameter in a URL. The vulnerability arises due to insufficient input sanitization, allowing arbitrary script execution in the context of the affected site.
This exploit demonstrates a cross-site scripting (XSS) vulnerability in GlassFish Enterprise Server 2.1 by injecting malicious JavaScript code via the 'name' parameter in the auditModuleEdit.jsf endpoint. The PoC uses a simple IMG tag with a JavaScript URI to trigger an alert, confirming the vulnerability.