Back to Database
Status published
Medium
CVE-2009-1524
Cross-site scripting (XSS) vulnerability in Mort Bay Jetty before 6.1.17...
Vulnerability Description
Cross-site scripting (XSS) vulnerability in Mort Bay Jetty before 6.1.17 allows remote attackers to inject arbitrary web script or HTML via a directory listing request containing a ; (semicolon) character.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2009-1524
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.securityfocus.com/bid/34800
- http://www.vupen.com/english/advisories/2010/1792
- http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02282388
- https://bugzilla.redhat.com/show_bug.cgi?id=499867
- http://secunia.com/advisories/34975
- http://secunia.com/advisories/40553
- http://jira.codehaus.org/browse/JETTY-980
- http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02282388
More from mortbay
View All →CVE-2009-5049
WebApp JSP Snoop page XSS in jetty though 6.1.21....
Medium
6.1
CVE-2009-5048
Cookie Dump Servlet stored XSS vulnerability in jetty though 6.1.20....
Medium
6.1
CVE-2009-4612
Multiple cross-site scripting (XSS) vulnerabilities in the WebApp JSP Snoop...
Medium
4.3
CVE-2009-4611
Mort Bay Jetty 6.x through 6.1.22 and 7.0.0 writes backtrace...
High
7.5
CVE-2009-4610
Multiple cross-site scripting (XSS) vulnerabilities in Mort Bay Jetty 6.x...
Medium
4.3
Affected Vendor
mortbay
View all reports →Affected Software
jetty
Vulnerable Versions:
0, 1.0, 1.0.1, 1.1, 1.1.1, 1.2.0, 1.3.0, 1.3.1, 1.3.2, 1.3.3, 1.3.4, 1.3.5, 2.0, 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, 2.1.0, 2.1.1, 2.1.2, 2.1.3, 2.1.4, 2.1.5, 2.1.6, 2.1.7, 2.1.b0, 2.1.b1, 2.2, 2.2.0, 2.2.1, 2.2.2, 2.2.3, 2.2.4, 2.2.5, 2.2.6, 2.2.7, 2.2.8, 2.3.0, 2.3.0a, 2.3.1, 2.3.2, 2.3.3, 2.3.4, 2.3.5, 2.4.0, 2.4.1, 2.4.2, 2.4.3, 2.4.4, 2.4.5, 2.4.6, 2.4.7, 2.4.8, 2.4.9, 3.0.0, 3.0.1, 3.0.2, 3.0.3, 3.0.4, 3.0.5, 3.0.6, 3.0.a0, 3.0.a1, 3.0.a2, 3.0.a3, 3.0.a4, 3.0.a5, 3.0.a6, 3.0.a7, 3.0.a8, 3.0.a9, 3.0.a90, 3.0.a91, 3.0.a92, 3.0.a93, 3.0.a94, 3.0.a95, 3.0.a96, 3.0.a97, 3.0.a98, 3.0.a99, 3.0.b01, 3.0.b02, 3.0.b03, 3.0.b04, 3.0.b05, 3.1, 3.1.0, 3.1.1, 3.1.2, 3.1.3, 3.1.4, 3.1.5, 3.1.6, 3.1.7, 3.1.8, 3.1.9, 4.0, 4.0.0, 4.0.1, 4.0.2, 4.0.3, 4.0.4, 4.0.5, 4.0.6, 4.0.b0, 4.0.b1, 4.0.b2, 4.0.d0, 4.0.d1, 4.0.d2, 4.0.d3, 4.0.d4, 4.1.0, 4.1.1, 4.1.2, 4.1.3, 4.1.4, 4.1.b0, 4.1.b1, 4.1.d0, 4.1.d1, 4.1.d2, 4.2.0, 4.2.1, 4.2.2, 4.2.3, 4.2.4, 4.2.5, 4.2.6, 4.2.7, 4.2.8_01, 4.2.9, 4.2.10, 4.2.12, 4.2.14, 4.2.15, 4.2.16, 4.2.17, 4.2.18, 4.2.19, 4.2.20, 4.2.21, 4.2.22, 4.2.23, 4.2.24, 4.2.25, 4.2.26, 4.2.27, 5.0, 5.0.0, 5.1, 5.1.0, 5.1.1, 5.1.2, 5.1.3, 5.1.4, 5.1.5, 5.1.6, 5.1.7, 5.1.8, 5.1.9, 5.1.10, 5.1.11, 5.1.12, 5.1.13, 5.1.14, 6.0.0, 6.0.1, 6.0.2, 6.1.0, 6.1.1, 6.1.2, 6.1.3, 6.1.4, 6.1.5, 6.1.6, 6.1.7, 6.1.8, 6.1.9, 6.1.10, 6.1.11, 6.1.12, 6.1.14, 6.1.15
Timeline
Official Publish:
May 5th, 2009
Last Modified:
August 7th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.