Jetty Servlet Engine Cross Site Scripting Vulnerability
BID:5821
Info
Jetty Servlet Engine Cross Site Scripting Vulnerability
| Bugtraq ID: | 5821 |
| Class: | Input Validation Error |
| CVE: |
CVE-2002-1533 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 28 2002 12:00AM |
| Updated: | Jul 11 2009 05:06PM |
| Credit: | Vulnerability discovery credited to <[email protected]>. |
| Vulnerable: |
Jetty Jetty 4.1 .0RC4 |
| Not Vulnerable: | |
Discussion
Jetty Servlet Engine Cross Site Scripting Vulnerability
Jetty is a freely available, open source Java Web Server and Servlet Container. It is available for Linux, Unix, and Microsoft Windows platforms.
It has been reported that Jetty does not properly sanitize requests. This could result in a user clicking a malicious link that would execute script or HTML code in the security context of the site hosted by the Jetty server. An attacker could exploit this vulnerability to gain authentication cookies, or other sensitive information.
Jetty is a freely available, open source Java Web Server and Servlet Container. It is available for Linux, Unix, and Microsoft Windows platforms.
It has been reported that Jetty does not properly sanitize requests. This could result in a user clicking a malicious link that would execute script or HTML code in the security context of the site hosted by the Jetty server. An attacker could exploit this vulnerability to gain authentication cookies, or other sensitive information.
Exploit / POC
Jetty Servlet Engine Cross Site Scripting Vulnerability
Contributed by <[email protected]>:
http://www.example.com/%0a%0a<script>alert("jax%20is%20ereet%20:P")</script>.jsp
Contributed by <[email protected]>:
http://www.example.com/%0a%0a<script>alert("jax%20is%20ereet%20:P")</script>.jsp
Solution / Fix
Jetty Servlet Engine Cross Site Scripting Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.