CVE Database
/

CVE-2009-1553

Back to search

CVE-2009-1553

Published: May 6, 2009

Modified: Aug 7, 2024

PUBLISHED

Description

Multiple cross-site scripting (XSS) vulnerabilities in the Admin Console in Sun GlassFish Enterprise Server 2.1 allow remote attackers to inject arbitrary web script or HTML via the query string to (1) applications/applications.jsf, (2) configuration/configuration.jsf, (3) customMBeans/customMBeans.jsf, (4) resourceNode/resources.jsf, (5) sysnet/registration.jsf, or (6) webService/webServicesGeneral.jsf; or the name parameter to (7) configuration/auditModuleEdit.jsf, (8) configuration/httpListenerEdit.jsf, or (9) resourceNode/jdbcResourceEdit.jsf.

VendorProductVersions

n/a

n/a

affected
n/a

References

258528
vendor-advisory
x_refsource_SUNALERT
54254
vdb-entry
x_refsource_OSVDB
54256
vdb-entry
x_refsource_OSVDB
54250
vdb-entry
x_refsource_OSVDB
54253
vdb-entry
x_refsource_OSVDB
54257
vdb-entry
x_refsource_OSVDB
JVNDB-2009-000027
third-party-advisory
x_refsource_JVNDB
ADV-2009-1255
vdb-entry
x_refsource_VUPEN
54252
vdb-entry
x_refsource_OSVDB
54255
vdb-entry
x_refsource_OSVDB
54249
vdb-entry
x_refsource_OSVDB
JVN#73653977
third-party-advisory
x_refsource_JVN
54251
vdb-entry
x_refsource_OSVDB
34824
vdb-entry
x_refsource_BID
34914
vdb-entry
x_refsource_BID

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now