4.3
CVSSv2

CVE-2014-1904

Published: 20/03/2014 Updated: 27/03/2019
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in web/servlet/tags/form/FormTag.java in Spring MVC in Spring Framework 3.0.0 prior to 3.2.8 and 4.0.0 prior to 4.0.2 allows remote malicious users to inject arbitrary web script or HTML via the requested URI in a default action.

Vulnerable Product Search on Vulmon Subscribe to Product

pivotal software spring framework

Vendor Advisories

Debian Bug report logs - #741604 libspring-java: Multiple security issues Package: libspring-java; Maintainer for libspring-java is Debian Java Maintainers <pkg-java-maintainers@listsaliothdebianorg>; Reported by: Moritz Muehlenhoff <jmm@inutilorg> Date: Fri, 14 Mar 2014 12:39:01 UTC Owned by: Miguel Landaeta < ...
Cross-site scripting (XSS) vulnerability in web/servlet/tags/form/FormTagjava in Spring MVC in Spring Framework 300 before 328 and 400 before 402 allows remote attackers to inject arbitrary web script or HTML via the requested URI in a default action ...

Github Repositories

Reproducible exploits for: CVE-2016-1240 CVE-2008-2938 CVE-2014-2064 CVE-2014-1904

Offensive technologies course This repository contains descriptions of several vulnerabilities and the code that exploits them Exploitable environments can be found in /dockerfiles/victim folder Attacker environments can be found in /dockerfiles/attacker folder Everything comes as Docker images Exploited CVEs: CVE-2008-2938 (Tomcat path traversal) CVE-2014-1904 (Spring pat