CVE-2013-6235

Steve Souza Java Application Monitor < 2.7 - XSS

Title source: rule

Description

Multiple cross-site scripting (XSS) vulnerabilities in JAMon (Java Application Monitor) 2.7 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) listenertype or (2) currentlistener parameter to mondetail.jsp or ArraySQL parameter to (3) mondetail.jsp, (4) jamonadmin.jsp, (5) sql.jsp, or (6) exceptions.jsp.

Scores

EPSS 0.0040
EPSS Percentile 60.1%

Details

CWE
CWE-79
Status published
Products (12)
steve_souza/java_application_monitor < 2.7
steve_souza/java_application_monitor
steve_souza/java_application_monitor
steve_souza/java_application_monitor
steve_souza/java_application_monitor
steve_souza/java_application_monitor
steve_souza/java_application_monitor
steve_souza/java_application_monitor
steve_souza/java_application_monitor
steve_souza/java_application_monitor
... and 2 more
Published Jan 31, 2014
Tracked Since Feb 18, 2026