CVE-2009-4612
Mort Bay Jetty 6.1.x-6.1.21 - XSS
Title source: llmDescription
Multiple cross-site scripting (XSS) vulnerabilities in the WebApp JSP Snoop page in Mort Bay Jetty 6.1.x through 6.1.21 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the default URI under (1) jspsnoop/, (2) jspsnoop/ERROR/, and (3) jspsnoop/IOException/, and possibly the PATH_INFO to (4) snoop.jsp.
Exploits (1)
Scores
EPSS
0.0013
EPSS Percentile
32.3%
Classification
CWE
CWE-79
Status
published
Affected Products (50)
mortbay/jetty
mortbay/jetty
mortbay/jetty
mortbay/jetty
mortbay/jetty
mortbay/jetty
mortbay/jetty
mortbay/jetty
mortbay/jetty
mortbay/jetty
mortbay/jetty
mortbay/jetty
mortbay/jetty
mortbay/jetty
mortbay/jetty
... and 35 more
Timeline
Published
Jan 13, 2010
Tracked Since
Feb 18, 2026