mirror of
https://github.com/0xMarcio/cve.git
synced 2025-05-30 18:20:53 +00:00
19 lines
769 B
Markdown
19 lines
769 B
Markdown
![]() |
### [CVE-2009-3579](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3579)
|
||
|

|
||
|

|
||
|

|
||
|
|
||
|
### Description
|
||
|
|
||
|
Cross-site scripting (XSS) vulnerability in the CookieDump.java sample application in Mort Bay Jetty 6.1.19 and 6.1.20 allows remote attackers to inject arbitrary web script or HTML via the Value parameter in a GET request to cookie/.
|
||
|
|
||
|
### POC
|
||
|
|
||
|
#### Reference
|
||
|
- http://www.coresecurity.com/content/jetty-persistent-xss
|
||
|
- http://www.ush.it/team/ush/hack-jetty6x7x/jetty-adv.txt
|
||
|
|
||
|
#### Github
|
||
|
No PoCs found on GitHub currently.
|
||
|
|