Show filters
15 Total Results
Displaying 1-10 of 15
Sort by:
Attacker Value
Unknown
CVE-2024-9823
Disclosure Date: October 14, 2024 (last updated October 15, 2024)
There exists a security vulnerability in Jetty's DosFilter which can be exploited by unauthorized users to cause remote denial-of-service (DoS) attack on the server using DosFilter. By repeatedly sending crafted requests, attackers can trigger OutofMemory errors and exhaust the server's memory finally.
0
Attacker Value
Unknown
CVE-2023-28748
Disclosure Date: November 06, 2023 (last updated November 10, 2023)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in biztechc Copy or Move Comments allows SQL Injection.This issue affects Copy or Move Comments: from n/a through 5.0.4.
0
Attacker Value
Unknown
CVE-2023-45634
Disclosure Date: October 25, 2023 (last updated October 28, 2023)
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Biztechc Copy or Move Comments plugin <= 5.0.4 versions.
0
Attacker Value
Unknown
CVE-2022-4295
Disclosure Date: January 16, 2023 (last updated October 08, 2023)
The Show All Comments WordPress plugin before 7.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against a logged in high privilege users such as admin.
0
Attacker Value
Unknown
CVE-2007-6672
Disclosure Date: January 08, 2008 (last updated October 04, 2023)
Mortbay Jetty 6.1.5 and 6.1.6 allows remote attackers to bypass protection mechanisms and read the source of files via multiple '/' (slash) characters in the URI.
0
Attacker Value
Unknown
CVE-2007-5614
Disclosure Date: December 05, 2007 (last updated October 04, 2023)
Mortbay Jetty before 6.1.6rc1 does not properly handle "certain quote sequences" in HTML cookie parameters, which allows remote attackers to hijack browser sessions via unspecified vectors.
0
Attacker Value
Unknown
CVE-2007-5615
Disclosure Date: December 05, 2007 (last updated October 04, 2023)
CRLF injection vulnerability in Mortbay Jetty before 6.1.6rc0 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.
0
Attacker Value
Unknown
CVE-2007-5613
Disclosure Date: December 05, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Dump Servlet in Mortbay Jetty before 6.1.6rc1 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters and cookies.
0
Attacker Value
Unknown
CVE-2006-6969
Disclosure Date: February 07, 2007 (last updated October 04, 2023)
Jetty before 4.2.27, 5.1 before 5.1.12, 6.0 before 6.0.2, and 6.1 before 6.1.0pre3 generates predictable session identifiers using java.util.random, which makes it easier for remote attackers to guess a session identifier through brute force attacks, bypass authentication requirements, and possibly conduct cross-site request forgery attacks.
0
Attacker Value
Unknown
CVE-2006-2759
Disclosure Date: June 02, 2006 (last updated October 04, 2023)
jetty 6.0.x (jetty6) beta16 allows remote attackers to read arbitrary script source code via a capital P in the .jsp extension, and probably other mixed case manipulations.
0