CVE-2009-4612

Mort Bay Jetty 6.1.x-6.1.21 - XSS

Title source: llm
STIX 2.1

Description

Multiple cross-site scripting (XSS) vulnerabilities in the WebApp JSP Snoop page in Mort Bay Jetty 6.1.x through 6.1.21 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the default URI under (1) jspsnoop/, (2) jspsnoop/ERROR/, and (3) jspsnoop/IOException/, and possibly the PATH_INFO to (4) snoop.jsp.

Exploits (1)

exploitdb WORKING POC VERIFIED
by aScii · textwebappsjsp
https://www.exploit-db.com/exploits/33564

References (1)

Core 1
Core References

Scores

EPSS 0.0013
EPSS Percentile 32.0%

Details

CWE
CWE-79
Status published
Products (18)
mortbay/jetty 6.1.0 (9 CPE variants)
mortbay/jetty 6.1.1 (2 CPE variants)
mortbay/jetty 6.1.2 (9 CPE variants)
mortbay/jetty 6.1.3
mortbay/jetty 6.1.4 (3 CPE variants)
mortbay/jetty 6.1.5 (2 CPE variants)
mortbay/jetty 6.1.6 (3 CPE variants)
mortbay/jetty 6.1.7
mortbay/jetty 6.1.8
mortbay/jetty 6.1.9
... and 8 more
Published Jan 13, 2010
Tracked Since Feb 18, 2026