[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Jetty 6.1.6 Cross Site Scripting Vulnerability

Author
1N3
Risk
[
Security Risk Low
]
0day-ID
0day-ID-30901
Category
web applications
Date add
16-08-2018
Platform
jsp
Title: Jetty 6.1.6 Cross-Site Scripting
Author: 1N3@CrowdShield - https://crowdshield
Software Link: http://www.mortbay.org/jetty/
Tested on: Jetty 6.1.6 (other versions may also be vulnerable)
CVE: N/A

Background: Jetty 6.1.6 is vulnerable to Cross-Site Scripting (XSS)
which allows an attacker to inject malicious code into the affected
site. 

An attacker can trigger the exploit by appending the following payload
to an affected web server which has an open directory listing enabled
(https://victim.com//..;/">").

#  0day.today [2024-09-29]  #