Lucene search

K
cveMitreCVE-2013-6235
HistoryJan 31, 2014 - 3:07 p.m.

CVE-2013-6235

2014-01-3115:07:35
CWE-79
mitre
web.nvd.nist.gov
49
cve-2013-6235
cross-site scripting
xss
jamon
java application monitor
nvd

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.7

Confidence

High

EPSS

0.004

Percentile

72.0%

Multiple cross-site scripting (XSS) vulnerabilities in JAMon (Java Application Monitor) 2.7 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) listenertype or (2) currentlistener parameter to mondetail.jsp or ArraySQL parameter to (3) mondetail.jsp, (4) jamonadmin.jsp, (5) sql.jsp, or (6) exceptions.jsp.

Affected configurations

Nvd
Node
steve_souzajava_application_monitorRange2.7
OR
steve_souzajava_application_monitorMatch1.0
OR
steve_souzajava_application_monitorMatch1.01
OR
steve_souzajava_application_monitorMatch2.0
OR
steve_souzajava_application_monitorMatch2.1
OR
steve_souzajava_application_monitorMatch2.2
OR
steve_souzajava_application_monitorMatch2.3
OR
steve_souzajava_application_monitorMatch2.4
OR
steve_souzajava_application_monitorMatch2.5
OR
steve_souzajava_application_monitorMatch2.6
VendorProductVersionCPE
steve_souzajava_application_monitor*cpe:2.3:a:steve_souza:java_application_monitor:*:*:*:*:*:*:*:*
steve_souzajava_application_monitor1.0cpe:2.3:a:steve_souza:java_application_monitor:1.0:*:*:*:*:*:*:*
steve_souzajava_application_monitor1.01cpe:2.3:a:steve_souza:java_application_monitor:1.01:*:*:*:*:*:*:*
steve_souzajava_application_monitor2.0cpe:2.3:a:steve_souza:java_application_monitor:2.0:*:*:*:*:*:*:*
steve_souzajava_application_monitor2.1cpe:2.3:a:steve_souza:java_application_monitor:2.1:*:*:*:*:*:*:*
steve_souzajava_application_monitor2.2cpe:2.3:a:steve_souza:java_application_monitor:2.2:*:*:*:*:*:*:*
steve_souzajava_application_monitor2.3cpe:2.3:a:steve_souza:java_application_monitor:2.3:*:*:*:*:*:*:*
steve_souzajava_application_monitor2.4cpe:2.3:a:steve_souza:java_application_monitor:2.4:*:*:*:*:*:*:*
steve_souzajava_application_monitor2.5cpe:2.3:a:steve_souza:java_application_monitor:2.5:*:*:*:*:*:*:*
steve_souzajava_application_monitor2.6cpe:2.3:a:steve_souza:java_application_monitor:2.6:*:*:*:*:*:*:*

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.7

Confidence

High

EPSS

0.004

Percentile

72.0%