Description
Multiple cross-site scripting (XSS) vulnerabilities in the WebApp JSP Snoop page in Mort Bay Jetty 6.1.x through 6.1.21 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the default URI under (1) jspsnoop/, (2) jspsnoop/ERROR/, and (3) jspsnoop/IOException/, and possibly the PATH_INFO to (4) snoop.jsp.
Exploits (1)
References (1)
Core 1
Core References
Exploit x_refsource_misc
http://www.ush.it/team/ush/hack-jetty6x7x/jetty-adv.txt
Scores
EPSS
0.0013
EPSS Percentile
32.0%
Details
CWE
CWE-79
Status
published
Products (18)
mortbay/jetty
6.1.0 (9 CPE variants)
mortbay/jetty
6.1.1 (2 CPE variants)
mortbay/jetty
6.1.2 (9 CPE variants)
mortbay/jetty
6.1.3
mortbay/jetty
6.1.4 (3 CPE variants)
mortbay/jetty
6.1.5 (2 CPE variants)
mortbay/jetty
6.1.6 (3 CPE variants)
mortbay/jetty
6.1.7
mortbay/jetty
6.1.8
mortbay/jetty
6.1.9
... and 8 more
Published
Jan 13, 2010
Tracked Since
Feb 18, 2026