4.3
CVSSv2

CVE-2009-1553

Published: 06/05/2009 Updated: 10/10/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 470
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in the Admin Console in Sun GlassFish Enterprise Server 2.1 allow remote malicious users to inject arbitrary web script or HTML via the query string to (1) applications/applications.jsf, (2) configuration/configuration.jsf, (3) customMBeans/customMBeans.jsf, (4) resourceNode/resources.jsf, (5) sysnet/registration.jsf, or (6) webService/webServicesGeneral.jsf; or the name parameter to (7) configuration/auditModuleEdit.jsf, (8) configuration/httpListenerEdit.jsf, or (9) resourceNode/jdbcResourceEdit.jsf.

Vulnerable Product Search on Vulmon Subscribe to Product

oracle glassfish server 2.1

Exploits

source: wwwsecurityfocuscom/bid/34824/info GlassFish Enterprise Server is prone to multiple cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied input Attacker-supplied HTML and script code would run in the context of the affected site, potentially allowing the attacker to steal cookie-based aut ...
source: wwwsecurityfocuscom/bid/34824/info GlassFish Enterprise Server is prone to multiple cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied input Attacker-supplied HTML and script code would run in the context of the affected site, potentially allowing the attacker to steal cookie-based authe ...
source: wwwsecurityfocuscom/bid/34824/info GlassFish Enterprise Server is prone to multiple cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied input Attacker-supplied HTML and script code would run in the context of the affected site, potentially allowing the attacker to steal cook ...
source: wwwsecurityfocuscom/bid/34824/info GlassFish Enterprise Server is prone to multiple cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied input Attacker-supplied HTML and script code would run in the context of the affected site, potentially allowing the attacker to steal cookie-bas ...
source: wwwsecurityfocuscom/bid/34824/info GlassFish Enterprise Server is prone to multiple cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied input Attacker-supplied HTML and script code would run in the context of the affected site, potentially allowing the attacker to steal cookie-based a ...
source: wwwsecurityfocuscom/bid/34824/info GlassFish Enterprise Server is prone to multiple cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied input Attacker-supplied HTML and script code would run in the context of the affected site, potentially allowing the attacker to steal cookie-b ...
source: wwwsecurityfocuscom/bid/34824/info GlassFish Enterprise Server is prone to multiple cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied input Attacker-supplied HTML and script code would run in the context of the affected site, potentially allowing the attacker to steal cookie ...
source: wwwsecurityfocuscom/bid/34824/info GlassFish Enterprise Server is prone to multiple cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied input Attacker-supplied HTML and script code would run in the context of the affected site, potentially allowing the attacker to steal cookie-based ...