CVE-2009-4612

Multiple cross-site scripting (XSS) vulnerabilities in the WebApp JSP Snoop page in Mort Bay Jetty 6.1.x through 6.1.21 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the default URI under (1) jspsnoop/, (2) jspsnoop/ERROR/, and (3) jspsnoop/IOException/, and possibly the PATH_INFO to (4) snoop.jsp.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 52%
VendorProductVersion
mortbayjetty
6.1.0
mortbayjetty
6.1.0:pre0
mortbayjetty
6.1.0:pre1
mortbayjetty
6.1.0:pre2
mortbayjetty
6.1.0:pre3
mortbayjetty
6.1.0:rc0
mortbayjetty
6.1.0:rc1
mortbayjetty
6.1.0:rc2
mortbayjetty
6.1.0:rc3
mortbayjetty
6.1.1
mortbayjetty
6.1.1:rc0
mortbayjetty
6.1.2
mortbayjetty
6.1.2:pre0
mortbayjetty
6.1.2:pre1
mortbayjetty
6.1.2:rc0
mortbayjetty
6.1.2:rc1
mortbayjetty
6.1.2:rc2
mortbayjetty
6.1.2:rc3
mortbayjetty
6.1.2:rc4
mortbayjetty
6.1.2:rc5
mortbayjetty
6.1.3
mortbayjetty
6.1.4
mortbayjetty
6.1.4:rc0
mortbayjetty
6.1.4:rc1
mortbayjetty
6.1.5
mortbayjetty
6.1.5:rc0
mortbayjetty
6.1.6
mortbayjetty
6.1.6:rc0
mortbayjetty
6.1.6:rc1
mortbayjetty
6.1.7
mortbayjetty
6.1.8
mortbayjetty
6.1.9
mortbayjetty
6.1.10
mortbayjetty
6.1.11
mortbayjetty
6.1.12
mortbayjetty
6.1.12:rc1
mortbayjetty
6.1.12:rc2
mortbayjetty
6.1.12:rc3
mortbayjetty
6.1.12:rc4
mortbayjetty
6.1.12:rc5
mortbayjetty
6.1.14
mortbayjetty
6.1.15
mortbayjetty
6.1.15:pre0
mortbayjetty
6.1.15:rc2
mortbayjetty
6.1.15:rc3
mortbayjetty
6.1.15:rc4
mortbayjetty
6.1.15:rc5
mortbayjetty
6.1.16
mortbayjetty
6.1.19
mortbayjetty
6.1.20
mortbayjetty
6.1.21
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
jetty
lucid
not-affected
karmic
not-affected
jaunty
not-affected
intrepid
ignored
hardy
not-affected
dapper
ignored