2023-04-24 12:24:31 +02:00
{
"id" : "CVE-2009-4612" ,
"sourceIdentifier" : "cve@mitre.org" ,
"published" : "2010-01-13T20:30:00.763" ,
2024-11-22 11:14:00 +00:00
"lastModified" : "2024-11-21T01:10:02.927" ,
"vulnStatus" : "Modified" ,
2024-12-08 03:06:42 +00:00
"cveTags" : [ ] ,
2023-04-24 12:24:31 +02:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "Multiple cross-site scripting (XSS) vulnerabilities in the WebApp JSP Snoop page in Mort Bay Jetty 6.1.x through 6.1.21 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the default URI under (1) jspsnoop/, (2) jspsnoop/ERROR/, and (3) jspsnoop/IOException/, and possibly the PATH_INFO to (4) snoop.jsp."
} ,
{
"lang" : "es" ,
"value" : "M\u00faltiples vulnerabilidades de ejecuci\u00f3n de secuencias de comandos en sitios cruzados en WebApp JSP Snoop page en Mort Bay Jetty v6.1.x a la v6.1.21, permite a atacantes remotos inyectar secuencias de comandos web o HTML de su elecci\u00f3n a trav\u00e9s de PATH_INFO a la URI por defecto bajo (1) jspsnoop/, (2) jspsnoop/ERROR/, y (3) jspsnoop/IOException/, y posiblemente a (4) snoop.jsp."
}
] ,
"metrics" : {
"cvssMetricV2" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "2.0" ,
"vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N" ,
2024-11-22 11:14:00 +00:00
"baseScore" : 4.3 ,
2023-04-24 12:24:31 +02:00
"accessVector" : "NETWORK" ,
"accessComplexity" : "MEDIUM" ,
"authentication" : "NONE" ,
"confidentialityImpact" : "NONE" ,
"integrityImpact" : "PARTIAL" ,
2024-11-22 11:14:00 +00:00
"availabilityImpact" : "NONE"
2023-04-24 12:24:31 +02:00
} ,
"baseSeverity" : "MEDIUM" ,
"exploitabilityScore" : 8.6 ,
"impactScore" : 2.9 ,
"acInsufInfo" : false ,
"obtainAllPrivilege" : false ,
"obtainUserPrivilege" : false ,
"obtainOtherPrivilege" : false ,
"userInteractionRequired" : true
}
]
} ,
"weaknesses" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-79"
}
]
}
] ,
"configurations" : [
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:mortbay:jetty:6.1.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "586B69D3-7734-4ECA-8E84-8FEB2A914471"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:mortbay:jetty:6.1.0:pre0:*:*:*:*:*:*" ,
"matchCriteriaId" : "D61DE1A4-36B9-4EDD-9628-B736318973C8"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:mortbay:jetty:6.1.0:pre1:*:*:*:*:*:*" ,
"matchCriteriaId" : "C981EEAA-1D2B-44BC-9ED5-D3851F31A67F"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:mortbay:jetty:6.1.0:pre2:*:*:*:*:*:*" ,
"matchCriteriaId" : "6A7D5DD4-EB54-4C4C-8090-421C3319EDEB"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:mortbay:jetty:6.1.0:pre3:*:*:*:*:*:*" ,
"matchCriteriaId" : "ADB640DA-460C-45EC-8F02-A03E055ED15F"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:mortbay:jetty:6.1.0:rc0:*:*:*:*:*:*" ,
"matchCriteriaId" : "079E0899-2130-431E-9805-013A8B853BEE"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:mortbay:jetty:6.1.0:rc1:*:*:*:*:*:*" ,
"matchCriteriaId" : "10681635-C15C-44C8-BFB5-67912D4D39E1"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:mortbay:jetty:6.1.0:rc2:*:*:*:*:*:*" ,
"matchCriteriaId" : "E75B9E0D-D7CD-47EA-AB0C-86645CA2DF54"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:mortbay:jetty:6.1.0:rc3:*:*:*:*:*:*" ,
"matchCriteriaId" : "A877189B-8D9E-4A09-AC1C-831D0E15E686"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:mortbay:jetty:6.1.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "A411147B-CE7E-4277-A5DF-83B90C4FC97D"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:mortbay:jetty:6.1.1:rc0:*:*:*:*:*:*" ,
"matchCriteriaId" : "0615E5DF-590A-454D-BEE3-ACEB16DD83E6"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:mortbay:jetty:6.1.2:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "B83BFC82-97CF-40FF-B087-3B2B2DC5EE4B"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:mortbay:jetty:6.1.2:pre0:*:*:*:*:*:*" ,
"matchCriteriaId" : "B5DE9EF1-22BC-4182-8905-038AA06F8A31"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:mortbay:jetty:6.1.2:pre1:*:*:*:*:*:*" ,
"matchCriteriaId" : "3DAB11DB-4B81-4DDA-A29F-DEE72658E903"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:mortbay:jetty:6.1.2:rc0:*:*:*:*:*:*" ,
"matchCriteriaId" : "2CCEF874-0F28-40F3-84D7-9B2F1510054A"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:mortbay:jetty:6.1.2:rc1:*:*:*:*:*:*" ,
"matchCriteriaId" : "84A6F86D-B74A-467E-A16C-25A255CC61D4"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:mortbay:jetty:6.1.2:rc2:*:*:*:*:*:*" ,
"matchCriteriaId" : "C1BC12C8-98F4-4F41-979C-540F08908199"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:mortbay:jetty:6.1.2:rc3:*:*:*:*:*:*" ,
"matchCriteriaId" : "B4B5666F-C034-4656-A2D8-5D804CA3AA66"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:mortbay:jetty:6.1.2:rc4:*:*:*:*:*:*" ,
"matchCriteriaId" : "F7EC937F-3C86-4E63-86E2-0118DAD15430"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:mortbay:jetty:6.1.2:rc5:*:*:*:*:*:*" ,
"matchCriteriaId" : "699F1242-4422-4134-B191-F42CA8EAA91E"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:mortbay:jetty:6.1.3:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "6B7810EC-58C5-4BB4-B2E5-6196364B3F22"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:mortbay:jetty:6.1.4:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "56644769-E21B-46E3-9131-4078500F9B91"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:mortbay:jetty:6.1.4:rc0:*:*:*:*:*:*" ,
"matchCriteriaId" : "812CC60A-71D8-47E2-BE60-BCE975418047"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:mortbay:jetty:6.1.4:rc1:*:*:*:*:*:*" ,
"matchCriteriaId" : "3B860EF7-0F72-45D6-B4B6-D3E29B07F88C"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:mortbay:jetty:6.1.5:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "A2C2A9E3-8C89-4D2D-AECA-55415DDD4BEF"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:mortbay:jetty:6.1.5:rc0:*:*:*:*:*:*" ,
"matchCriteriaId" : "F3550007-F89A-4164-BA45-30104347E463"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:mortbay:jetty:6.1.6:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "5A8E5744-F4FB-4D67-9DEA-938FDC66B7FA"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:mortbay:jetty:6.1.6:rc0:*:*:*:*:*:*" ,
"matchCriteriaId" : "80BFA8A6-2EC8-4BD4-BAA8-768246EC277F"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:mortbay:jetty:6.1.6:rc1:*:*:*:*:*:*" ,
"matchCriteriaId" : "CC92AA15-22D9-4213-BC7D-C36FBE4B249D"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:mortbay:jetty:6.1.7:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "DC998D08-61EC-45EE-AC67-41CB2B96BF70"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:mortbay:jetty:6.1.8:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "717F839C-2DDC-4D1F-84EE-8F87F4030904"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:mortbay:jetty:6.1.9:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "66649F13-2EAE-4F76-B21C-585C57921655"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:mortbay:jetty:6.1.10:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "BBD66FB6-F007-46DA-82B6-5083C75E5C07"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:mortbay:jetty:6.1.11:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "2D85A1B1-4E94-4F7C-B363-1F8C18999E76"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:mortbay:jetty:6.1.12:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "DF21570D-1EEF-4254-9BF2-8CAE8B408407"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:mortbay:jetty:6.1.12:rc1:*:*:*:*:*:*" ,
"matchCriteriaId" : "01A59DB6-B292-4040-9945-5ADADFBDFC6B"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:mortbay:jetty:6.1.12:rc2:*:*:*:*:*:*" ,
"matchCriteriaId" : "41419D41-EE7A-4464-94E7-847BD72EAAE2"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:mortbay:jetty:6.1.12:rc3:*:*:*:*:*:*" ,
"matchCriteriaId" : "5E16D7BC-9BCE-4FFD-9289-E7D951DA254A"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:mortbay:jetty:6.1.12:rc4:*:*:*:*:*:*" ,
"matchCriteriaId" : "859687C2-C15E-4D6B-B109-39F9AE80397C"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:mortbay:jetty:6.1.12:rc5:*:*:*:*:*:*" ,
"matchCriteriaId" : "F6563B61-601D-4C8A-9572-BD848C3A8313"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:mortbay:jetty:6.1.14:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "D05A27CC-C36F-425A-B72B-8F3DE19D5587"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:mortbay:jetty:6.1.15:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "76857BA7-99D9-489B-8ED5-292DAA083931"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:mortbay:jetty:6.1.15:pre0:*:*:*:*:*:*" ,
"matchCriteriaId" : "2C4AE268-006A-4EDE-8D2E-3CCD35F8EC7B"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:mortbay:jetty:6.1.15:rc2:*:*:*:*:*:*" ,
"matchCriteriaId" : "8F726A16-C432-4679-A904-37C0FE820883"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:mortbay:jetty:6.1.15:rc3:*:*:*:*:*:*" ,
"matchCriteriaId" : "81586EBF-EDFB-42C9-B5E2-BE29B66CE968"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:mortbay:jetty:6.1.15:rc4:*:*:*:*:*:*" ,
"matchCriteriaId" : "20E0FB52-1B22-46E5-B83D-D88513A3E314"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:mortbay:jetty:6.1.15:rc5:*:*:*:*:*:*" ,
"matchCriteriaId" : "1D9C76FD-3612-410F-AB14-A36D2C520439"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:mortbay:jetty:6.1.16:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "F1A35CE4-EAA9-4CDB-A54D-79AA844AF279"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:mortbay:jetty:6.1.19:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "8F616992-6D50-457F-B699-D0DCA3D46C33"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:mortbay:jetty:6.1.20:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "DAE13225-F90F-4ABC-87A0-DBE63E91FC18"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:mortbay:jetty:6.1.21:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "2CC32E7B-FCFD-492A-970C-FA4C4AD49709"
}
]
}
]
}
] ,
"references" : [
{
"url" : "http://www.ush.it/team/ush/hack-jetty6x7x/jetty-adv.txt" ,
"source" : "cve@mitre.org" ,
"tags" : [
"Exploit"
]
2024-11-22 11:14:00 +00:00
} ,
{
"url" : "http://www.ush.it/team/ush/hack-jetty6x7x/jetty-adv.txt" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Exploit"
]
2023-04-24 12:24:31 +02:00
}
]
}