CVE-2009-4612

Mort Bay Jetty 6.1.x-6.1.21 - XSS

Title source: llm

Description

Multiple cross-site scripting (XSS) vulnerabilities in the WebApp JSP Snoop page in Mort Bay Jetty 6.1.x through 6.1.21 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the default URI under (1) jspsnoop/, (2) jspsnoop/ERROR/, and (3) jspsnoop/IOException/, and possibly the PATH_INFO to (4) snoop.jsp.

Exploits (1)

exploitdb WORKING POC VERIFIED
by aScii · textwebappsjsp
https://www.exploit-db.com/exploits/33564

Scores

EPSS 0.0013
EPSS Percentile 32.3%

Classification

CWE
CWE-79
Status published

Affected Products (50)

mortbay/jetty
mortbay/jetty
mortbay/jetty
mortbay/jetty
mortbay/jetty
mortbay/jetty
mortbay/jetty
mortbay/jetty
mortbay/jetty
mortbay/jetty
mortbay/jetty
mortbay/jetty
mortbay/jetty
mortbay/jetty
mortbay/jetty
... and 35 more

Timeline

Published Jan 13, 2010
Tracked Since Feb 18, 2026