CVE-2008-2751
Molteplici vulnerabilità di cross-site scripting (XSS) nell'interfaccia di amministrazione web di Glassfish in Sun Java System Application Server 9.1_01...
- Pubblicato
- 18 giu 2008
- Aggiornato
- 7 ago 2024
- Assegnazione CNA
- mitre
- Evidenza osservata
- 16 giu 2008
CVSS primario
nvd · CVSS 2.0
AV:N/AC:M/Au:N/C:N/I:P/A:NBasso · prossimi 30 giorni
- Percentile
- 91,6%
- Data del modello
- 21 set 2026
L'EPSS è una stima statistica, non una certezza o una misura di impatto. Combinalo con CVSS, stato KEV, esposizione e ambiente.
Riepilogo
Molteplici vulnerabilità di cross-site scripting (XSS) nell'interfaccia di amministrazione web di Glassfish in Sun Java System Application Server 9.1_01 consentono a un attaccante remoto di iniettare script web o HTML arbitrari tramite i parametri (1) propertyForm:propertyContentPage:propertySheet:propertSectionTextField:jndiProp:JndiNew, (2) propertyForm:propertyContentPage:propertySheet:propertSectionTextField:resTypeProp:resType, (3) propertyForm:propertyContentPage:propertySheet:propertSectionTextField:factoryClassProp:factoryClass, o (4) propertyForm:propertyContentPage:propertySheet:propertSectionTextField:descProp:desc verso (a) resourceNode/customResourceNew.jsf; i parametri (5) propertyForm:propertyContentPage:propertySheet:propertSectionTextField:jndiProp:JndiNew, (6) propertyForm:propertyContentPage:propertySheet:propertSectionTextField:resTypeProp:resType, (7) propertyForm:propertyContentPage:propertySheet:propertSectionTextField:factoryClassProp:factoryClass, (8) propertyForm:propertyContentPage:propertySheet:propertSectionTextField:jndiLookupProp:jndiLookup, o (9) propertyForm:propertyContentPage:propertySheet:propertSectionTextField:descProp:desc verso (b) resourceNode/externalResourceNew.jsf; i parametri (10) propertyForm:propertySheet:propertSectionTextField:jndiProp:Jndi, (11) propertyForm:propertySheet:propertSectionTextField:nameProp:name, o (12) propertyForm:propertySheet:propertSectionTextField:descProp:desc verso (c) resourceNode/jmsDestinationNew.jsf; i parametri (13) propertyForm:propertySheet:generalPropertySheet:jndiProp:Jndi o (14) propertyForm:propertySheet:generalPropertySheet:descProp:cd verso (d) resourceNode/jmsConnectionNew.jsf; i parametri (15) propertyForm:propertySheet:propertSectionTextField:jndiProp:jnditext o (16) propertyForm:propertySheet:propertSectionTextField:descProp:desc verso (e) resourceNode/jdbcResourceNew.jsf; i parametri (17) propertyForm:propertyContentPage:propertySheet:propertSectionTextField:nameProp:name, (18) propertyForm:propertyContentPage:propertySheet:propertSectionTextField:classNameProp:classname, o (19) propertyForm:propertyContentPage:propertySheet:propertSectionTextField:loadOrderProp:loadOrder verso (f) applications/lifecycleModulesNew.jsf; oppure i parametri (20) propertyForm:propertyContentPage:propertySheet:generalPropertySheet:jndiProp:name, (21) propertyForm:propertyContentPage:propertySheet:generalPropertySheet:resTypeProp:resType, o (22) propertyForm:propertyContentPage:propertySheet:generalPropertySheet:dbProp:db verso (g) resourceNode/jdbcConnectionPoolNew1.jsf.
Utilizzo responsabile
Utilizza le informazioni sulla vulnerabilità solo sui sistemi che possiedi o che sei autorizzato a testare. Kitploit si collega ai metadati della ricerca pubblica e non memorizza codici exploit o payload dannosi.