Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2009-4610


Multiple cross-site scripting (XSS) vulnerabilities in Mort Bay Jetty 6.x and 7.0.0 allow remote attackers to inject arbitrary web script or HTML via (1) the query string to jsp/dump.jsp in the JSP Dump feature, or the (2) Name or (3) Value parameter to the default URI for the Session Dump Servlet under session/.


Published

2010-01-13T20:30:00.703

Last Modified

2025-04-09T00:30:58.490

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 4.3 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:N/I:P/A:N

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

8.6

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application mortbay jetty 6.0.0 Yes
Application mortbay jetty 6.0.0 Yes
Application mortbay jetty 6.0.0 Yes
Application mortbay jetty 6.0.0 Yes
Application mortbay jetty 6.0.0 Yes
Application mortbay jetty 6.0.0 Yes
Application mortbay jetty 6.0.0 Yes
Application mortbay jetty 6.0.0 Yes
Application mortbay jetty 6.0.0 Yes
Application mortbay jetty 6.0.0 Yes
Application mortbay jetty 6.0.0 Yes
Application mortbay jetty 6.0.0 Yes
Application mortbay jetty 6.0.0 Yes
Application mortbay jetty 6.0.0 Yes
Application mortbay jetty 6.0.0 Yes
Application mortbay jetty 6.0.0 Yes
Application mortbay jetty 6.0.0 Yes
Application mortbay jetty 6.0.0 Yes
Application mortbay jetty 6.0.0 Yes
Application mortbay jetty 6.0.0 Yes
Application mortbay jetty 6.0.0 Yes
Application mortbay jetty 6.0.0 Yes
Application mortbay jetty 6.0.0 Yes
Application mortbay jetty 6.0.0 Yes
Application mortbay jetty 6.0.0 Yes
Application mortbay jetty 6.0.0 Yes
Application mortbay jetty 6.0.0 Yes
Application mortbay jetty 6.0.0 Yes
Application mortbay jetty 6.0.1 Yes
Application mortbay jetty 6.0.2 Yes
Application mortbay jetty 6.1.0 Yes
Application mortbay jetty 6.1.0 Yes
Application mortbay jetty 6.1.0 Yes
Application mortbay jetty 6.1.0 Yes
Application mortbay jetty 6.1.0 Yes
Application mortbay jetty 6.1.0 Yes
Application mortbay jetty 6.1.0 Yes
Application mortbay jetty 6.1.0 Yes
Application mortbay jetty 6.1.0 Yes
Application mortbay jetty 6.1.1 Yes
Application mortbay jetty 6.1.1 Yes
Application mortbay jetty 6.1.2 Yes
Application mortbay jetty 6.1.2 Yes
Application mortbay jetty 6.1.2 Yes
Application mortbay jetty 6.1.2 Yes
Application mortbay jetty 6.1.2 Yes
Application mortbay jetty 6.1.2 Yes
Application mortbay jetty 6.1.2 Yes
Application mortbay jetty 6.1.2 Yes
Application mortbay jetty 6.1.2 Yes
Application mortbay jetty 6.1.3 Yes
Application mortbay jetty 6.1.4 Yes
Application mortbay jetty 6.1.4 Yes
Application mortbay jetty 6.1.4 Yes
Application mortbay jetty 6.1.5 Yes
Application mortbay jetty 6.1.5 Yes
Application mortbay jetty 6.1.6 Yes
Application mortbay jetty 6.1.6 Yes
Application mortbay jetty 6.1.6 Yes
Application mortbay jetty 6.1.7 Yes
Application mortbay jetty 6.1.8 Yes
Application mortbay jetty 6.1.9 Yes
Application mortbay jetty 6.1.10 Yes
Application mortbay jetty 6.1.11 Yes
Application mortbay jetty 6.1.12 Yes
Application mortbay jetty 6.1.12 Yes
Application mortbay jetty 6.1.12 Yes
Application mortbay jetty 6.1.12 Yes
Application mortbay jetty 6.1.12 Yes
Application mortbay jetty 6.1.12 Yes
Application mortbay jetty 6.1.14 Yes
Application mortbay jetty 6.1.15 Yes
Application mortbay jetty 6.1.15 Yes
Application mortbay jetty 6.1.15 Yes
Application mortbay jetty 6.1.15 Yes
Application mortbay jetty 6.1.15 Yes
Application mortbay jetty 6.1.15 Yes
Application mortbay jetty 6.1.16 Yes
Application mortbay jetty 6.1.19 Yes
Application mortbay jetty 6.1.20 Yes
Application mortbay jetty 7.0.0 Yes

References