Show filters
19 Total Results
Displaying 11-19 of 19
Sort by:
Attacker Value
Unknown

CVE-2009-3579

Disclosure Date: October 07, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the CookieDump.java sample application in Mort Bay Jetty 6.1.19 and 6.1.20 allows remote attackers to inject arbitrary web script or HTML via the Value parameter in a GET request to cookie/.
0
Attacker Value
Unknown

CVE-2009-1523

Disclosure Date: May 05, 2009 (last updated October 04, 2023)
Directory traversal vulnerability in the HTTP server in Mort Bay Jetty 5.1.14, 6.x before 6.1.17, and 7.x through 7.0.0.M2 allows remote attackers to access arbitrary files via directory traversal sequences in the URI.
0
Attacker Value
Unknown

CVE-2009-1524

Disclosure Date: May 05, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Mort Bay Jetty before 6.1.17 allows remote attackers to inject arbitrary web script or HTML via a directory listing request containing a ; (semicolon) character.
0
Attacker Value
Unknown

CVE-2007-6672

Disclosure Date: January 08, 2008 (last updated October 04, 2023)
Mortbay Jetty 6.1.5 and 6.1.6 allows remote attackers to bypass protection mechanisms and read the source of files via multiple '/' (slash) characters in the URI.
0
Attacker Value
Unknown

CVE-2007-5614

Disclosure Date: December 05, 2007 (last updated October 04, 2023)
Mortbay Jetty before 6.1.6rc1 does not properly handle "certain quote sequences" in HTML cookie parameters, which allows remote attackers to hijack browser sessions via unspecified vectors.
0
Attacker Value
Unknown

CVE-2007-5613

Disclosure Date: December 05, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Dump Servlet in Mortbay Jetty before 6.1.6rc1 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters and cookies.
0
Attacker Value
Unknown

CVE-2006-6969

Disclosure Date: February 07, 2007 (last updated October 04, 2023)
Jetty before 4.2.27, 5.1 before 5.1.12, 6.0 before 6.0.2, and 6.1 before 6.1.0pre3 generates predictable session identifiers using java.util.random, which makes it easier for remote attackers to guess a session identifier through brute force attacks, bypass authentication requirements, and possibly conduct cross-site request forgery attacks.
0
Attacker Value
Unknown

CVE-2006-2759

Disclosure Date: June 02, 2006 (last updated October 04, 2023)
jetty 6.0.x (jetty6) beta16 allows remote attackers to read arbitrary script source code via a capital P in the .jsp extension, and probably other mixed case manipulations.
0
Attacker Value
Unknown

CVE-2006-2758

Disclosure Date: June 02, 2006 (last updated October 04, 2023)
Directory traversal vulnerability in jetty 6.0.x (jetty6) beta16 allows remote attackers to read arbitrary files via a %2e%2e%5c (encoded ../) in the URL. NOTE: this might be the same issue as CVE-2005-3747.
0