CVE-2009-1554
N/A
N/A
Summary
Cross-site scripting (XSS) vulnerability in ThemeServlet.java in Sun Woodstock 4.2, as used in Sun GlassFish Enterprise Server and other products, allows remote attackers to inject arbitrary web script or HTML via a UTF-7 string in the PATH_INFO, which is displayed on the 404 error page, as demonstrated by the PATH_INFO to theme/META-INF.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- http://www.nabble.com/-DSECRG–Sun-Glassfish-Multiple-Security-Vulnerabilities-p22595435.html
- http://www.securityfocus.com/bid/34829
- http://www.nabble.com/Re:–DSECRG–Sun-Glassfish-Multiple-Security-Vulnerabilities-p23002524.html
- http://www.securityfocus.com/archive/1/503239/100/0/threaded
- http://secunia.com/advisories/35006
- http://osvdb.org/54220
- https://exchange.xforce.ibmcloud.com/vulnerabilities/50336
- https://woodstock.dev.java.net/servlets/ReadMsg?list=cvs&msgNo=4041
- http://dsecrg.com/pages/vul/show.php?id=138
References
- http://www.nabble.com/-DSECRG–Sun-Glassfish-Multiple-Security-Vulnerabilities-p22595435.html
- http://www.securityfocus.com/bid/34829
- http://www.nabble.com/Re:–DSECRG–Sun-Glassfish-Multiple-Security-Vulnerabilities-p23002524.html
- http://www.securityfocus.com/archive/1/503239/100/0/threaded
- http://secunia.com/advisories/35006
- http://osvdb.org/54220
- https://exchange.xforce.ibmcloud.com/vulnerabilities/50336
- https://woodstock.dev.java.net/servlets/ReadMsg?list=cvs&msgNo=4041
- http://dsecrg.com/pages/vul/show.php?id=138
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.