Lucene search

K
cve[email protected]CVE-2009-4610
HistoryOct 03, 2022 - 4:24 p.m.

CVE-2009-4610

2022-10-0316:24:04
CWE-79
web.nvd.nist.gov
41
cve-2009-4610
xss
mort bay jetty
cross-site scripting
vulnerabilities
security
nvd

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.2

Confidence

High

EPSS

0.001

Percentile

45.9%

Multiple cross-site scripting (XSS) vulnerabilities in Mort Bay Jetty 6.x and 7.0.0 allow remote attackers to inject arbitrary web script or HTML via (1) the query string to jsp/dump.jsp in the JSP Dump feature, or the (2) Name or (3) Value parameter to the default URI for the Session Dump Servlet under session/.

Affected configurations

NVD
Node
mortbayjettyMatch6.0.0
OR
mortbayjettyMatch6.0.0alpha0
OR
mortbayjettyMatch6.0.0alpha1
OR
mortbayjettyMatch6.0.0alpha2
OR
mortbayjettyMatch6.0.0alpha3
OR
mortbayjettyMatch6.0.0beta0
OR
mortbayjettyMatch6.0.0beta1
OR
mortbayjettyMatch6.0.0beta10
OR
mortbayjettyMatch6.0.0beta11
OR
mortbayjettyMatch6.0.0beta12
OR
mortbayjettyMatch6.0.0beta14
OR
mortbayjettyMatch6.0.0beta15
OR
mortbayjettyMatch6.0.0beta16
OR
mortbayjettyMatch6.0.0beta17
OR
mortbayjettyMatch6.0.0beta2
OR
mortbayjettyMatch6.0.0beta3
OR
mortbayjettyMatch6.0.0beta4
OR
mortbayjettyMatch6.0.0beta5
OR
mortbayjettyMatch6.0.0beta6
OR
mortbayjettyMatch6.0.0beta7
OR
mortbayjettyMatch6.0.0beta8
OR
mortbayjettyMatch6.0.0beta9
OR
mortbayjettyMatch6.0.0betax
OR
mortbayjettyMatch6.0.0rc0
OR
mortbayjettyMatch6.0.0rc1
OR
mortbayjettyMatch6.0.0rc2
OR
mortbayjettyMatch6.0.0rc3
OR
mortbayjettyMatch6.0.0rc4
OR
mortbayjettyMatch6.0.1
OR
mortbayjettyMatch6.0.2
OR
mortbayjettyMatch6.1.0
OR
mortbayjettyMatch6.1.0pre0
OR
mortbayjettyMatch6.1.0pre1
OR
mortbayjettyMatch6.1.0pre2
OR
mortbayjettyMatch6.1.0pre3
OR
mortbayjettyMatch6.1.0rc0
OR
mortbayjettyMatch6.1.0rc1
OR
mortbayjettyMatch6.1.0rc2
OR
mortbayjettyMatch6.1.0rc3
OR
mortbayjettyMatch6.1.1
OR
mortbayjettyMatch6.1.1rc0
OR
mortbayjettyMatch6.1.2
OR
mortbayjettyMatch6.1.2pre0
OR
mortbayjettyMatch6.1.2pre1
OR
mortbayjettyMatch6.1.2rc0
OR
mortbayjettyMatch6.1.2rc1
OR
mortbayjettyMatch6.1.2rc2
OR
mortbayjettyMatch6.1.2rc3
OR
mortbayjettyMatch6.1.2rc4
OR
mortbayjettyMatch6.1.2rc5
OR
mortbayjettyMatch6.1.3
OR
mortbayjettyMatch6.1.4
OR
mortbayjettyMatch6.1.4rc0
OR
mortbayjettyMatch6.1.4rc1
OR
mortbayjettyMatch6.1.5
OR
mortbayjettyMatch6.1.5rc0
OR
mortbayjettyMatch6.1.6
OR
mortbayjettyMatch6.1.6rc0
OR
mortbayjettyMatch6.1.6rc1
OR
mortbayjettyMatch6.1.7
OR
mortbayjettyMatch6.1.8
OR
mortbayjettyMatch6.1.9
OR
mortbayjettyMatch6.1.10
OR
mortbayjettyMatch6.1.11
OR
mortbayjettyMatch6.1.12
OR
mortbayjettyMatch6.1.12rc1
OR
mortbayjettyMatch6.1.12rc2
OR
mortbayjettyMatch6.1.12rc3
OR
mortbayjettyMatch6.1.12rc4
OR
mortbayjettyMatch6.1.12rc5
OR
mortbayjettyMatch6.1.14
OR
mortbayjettyMatch6.1.15
OR
mortbayjettyMatch6.1.15pre0
OR
mortbayjettyMatch6.1.15rc2
OR
mortbayjettyMatch6.1.15rc3
OR
mortbayjettyMatch6.1.15rc4
OR
mortbayjettyMatch6.1.15rc5
OR
mortbayjettyMatch6.1.16
OR
mortbayjettyMatch6.1.19
OR
mortbayjettyMatch6.1.20
OR
mortbayjettyMatch7.0.0

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.2

Confidence

High

EPSS

0.001

Percentile

45.9%