CVE-2009-1554
SUN Woodstock - XSS
Title source: ruleDescription
Cross-site scripting (XSS) vulnerability in ThemeServlet.java in Sun Woodstock 4.2, as used in Sun GlassFish Enterprise Server and other products, allows remote attackers to inject arbitrary web script or HTML via a UTF-7 string in the PATH_INFO, which is displayed on the 404 error page, as demonstrated by the PATH_INFO to theme/META-INF.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by DSecRG · textremotemultiple
https://www.exploit-db.com/exploits/32987
References (9)
Scores
EPSS
0.0156
EPSS Percentile
81.2%
Classification
CWE
CWE-79
Status
draft
Affected Products (1)
sun/woodstock
Timeline
Published
May 06, 2009
Tracked Since
Feb 18, 2026