Show filters
3 Total Results
Displaying 1-3 of 3
Sort by:
Attacker Value
Unknown
CVE-2018-15531
Disclosure Date: September 26, 2018 (last updated November 27, 2024)
JavaMelody before 1.74.0 has XXE via parseSoapMethodName in bull/javamelody/PayloadNameRequestWrapper.java.
0
Attacker Value
Unknown
CVE-2018-12432
Disclosure Date: June 14, 2018 (last updated November 26, 2024)
JavaMelody through 1.60.0 has XSS via the counter parameter in a clear_counter action to the /monitoring URI.
0
Attacker Value
Unknown
CVE-2013-4378
Disclosure Date: September 30, 2013 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in HtmlSessionInformationsReport.java in JavaMelody 1.46 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted X-Forwarded-For header.
0