CVE-2008-2751 (Java System Application Server, glassfish) [Sitemap] - HeapOverflow Computer Security Community & Forums : Heap Overflow.com

PDA

View Full Version : CVE-2008-2751 (Java System Application Server, glassfish)


Heap
19-06-08, 01:21
Multiple cross-site scripting (XSS) vulnerabilities in the Glassfish webadmin interface in Sun Java System Application Server 9.1_01 allow remote attackers to inject arbitrary web script or HTML via the (1) propertyForm:propertyContentPage:propertySheet:pro pertSectionTextField:jndiProp:JndiNew, (2) propertyForm:propertyContentPage:propertySheet:pro pertSectionTextField:resTypeProp:resType, (3) propertyForm:propertyContentPage:propertySheet:pro pertSectionTextField:factoryClassProp:factoryClass ,...

More... (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-2751)