PoC Index

CVE-2009-0038

MEDIUM 4.3EPSS 18.0%

Multiple cross-site scripting (XSS) vulnerabilities in the web administration console in Apache Geronimo Application Server 2.1 through 2.1.3 allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) ip, (3) username, or (4) description parameter to console/portal/Server/Monitoring; or (5) the PATH_INFO to the default URI under console/portal/.

CVSS v2.0
4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS
18.00% chance of exploitation in the next 30 days, 97th percentile
Published
2009-04-17
Updated
2024-08-07

ExploitDB entries (2)

References

Related