Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
apache jetspeed vulnerabilities and exploits
(subscribe to this query)
9
CVSSv2
CVE-2016-0709
Directory traversal vulnerability in the Import/Export function in the Portal Site Manager in Apache Jetspeed prior to 2.3.1 allows remote authenticated administrators to write to arbitrary files, and consequently execute arbitrary code, via a .. (dot dot) in a ZIP archive entry,...
Apache Jetspeed
1 EDB exploit
4.3
CVSSv2
CVE-2016-0711
Multiple cross-site scripting (XSS) vulnerabilities in Apache Jetspeed prior to 2.3.1 allow remote malicious users to inject arbitrary web script or HTML via the title parameter when adding a (1) link, (2) page, or (3) folder resource.
Apache Jetspeed
7.5
CVSSv2
CVE-2022-32533
Apache Jetspeed-2 does not sufficiently filter untrusted user input by default leading to a number of issues including XSS, CSRF, XXE, and SSRF. Setting the configuration option "xss.filter.post = true" may mitigate these issues. NOTE: Apache Jetspeed is a dormant proje...
Apache Jetspeed
7.5
CVSSv2
CVE-2016-0710
Multiple SQL injection vulnerabilities in the User Manager service in Apache Jetspeed prior to 2.3.1 allow remote malicious users to execute arbitrary SQL commands via the (1) role or (2) user parameter to services/usermanager/users/.
Apache Jetspeed
1 EDB exploit
4.3
CVSSv2
CVE-2016-0712
Cross-site scripting (XSS) vulnerability in Apache Jetspeed prior to 2.3.1 allows remote malicious users to inject arbitrary web script or HTML via the PATH_INFO to portal.
Apache Jetspeed
6.4
CVSSv2
CVE-2016-2171
The User Manager service in Apache Jetspeed prior to 2.3.1 does not properly restrict access using Jetspeed Security, which allows remote malicious users to (1) add, (2) edit, or (3) delete users via the REST API.
Apache Jetspeed
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
authentication bypass
CVE-2024-30043
camera
CVE-2023-40404
CVE-2024-2793
client side
CVE-2024-4469
CVE-2024-3565
CVE-2024-29825
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started