Jetty JSP Snoop Page Multiple Cross-Site Scripting Vulnerabilities
BID:37927
Info
Jetty JSP Snoop Page Multiple Cross-Site Scripting Vulnerabilities
| Bugtraq ID: | 37927 |
| Class: | Input Validation Error |
| CVE: |
CVE-2009-4612 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 24 2009 12:00AM |
| Updated: | Mar 19 2015 08:51AM |
| Credit: | Francesco "ascii" Ongaro (ascii AT ush DOT it), Giovanni "evilaliv3" Pellerano (evilaliv3 AT ush DOT it), and Antonio "s4tan" Parata (s4tan AT ush DOT it) |
| Vulnerable: |
Mort Bay Jetty 6.1.21 Mort Bay Jetty 6.1.17 Mort Bay Jetty 6.1.16 Mort Bay Jetty 6.1.6 Mort Bay Jetty 6.1.6 RC1 Mort Bay Jetty 6.1.6 RC0 Jetty Jetty 6.1.17 Jetty Jetty 6.1.16 Jetty Jetty 6.1.7 Jetty Jetty 6.1.6 Jetty Jetty 6.1.5 Jetty Jetty 6.1.4 Jetty Jetty 6.1.3 Jetty Jetty 6.1.2 Jetty Jetty 6.1.1 Jetty Jetty 6.1.0pre3 Jetty Jetty 6.1.0pre2 |
| Not Vulnerable: | |
Discussion
Jetty JSP Snoop Page Multiple Cross-Site Scripting Vulnerabilities
Jetty is prone to multiple cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied data.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Jetty is prone to multiple cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied data.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Exploit / POC
Jetty JSP Snoop Page Multiple Cross-Site Scripting Vulnerabilities
To exploit these issues, an attacker must entice an unsuspecting victim into following a malicious URI.
The following example URIs are available:
To exploit these issues, an attacker must entice an unsuspecting victim into following a malicious URI.
The following example URIs are available:
References
Jetty JSP Snoop Page Multiple Cross-Site Scripting Vulnerabilities
References:
References:
- Jetty 6.x and 7.x Multiple Vulnerabilities (Francesco "ascii" Ongaro (ascii AT ush DOT it))
- Jetty Homepage (Jetty)