CVE-2009-1524: XSS
Cross-site scripting (XSS) vulnerability in Mort Bay Jetty before 6.1.17 allows remote attackers to inject arbitrary web script or HTML via a directory listing request containing a ; (semicolon) character.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-1524?
CVE-2009-1524 is classified as a high severity Cross-site Scripting (XSS) vulnerability affecting Mort Bay Jetty versions before 6.1.17.
How do I fix CVE-2009-1524?
To fix CVE-2009-1524, upgrade to Mort Bay Jetty version 6.1.17 or later.
What kind of attack is possible with CVE-2009-1524?
CVE-2009-1524 allows remote attackers to inject arbitrary web scripts or HTML via malicious directory listing requests.
Which versions of Mort Bay Jetty are affected by CVE-2009-1524?
CVE-2009-1524 affects Mort Bay Jetty versions prior to 6.1.17, including all versions up to 6.1.16.
How can I detect if my system is vulnerable to CVE-2009-1524?
You can detect vulnerability to CVE-2009-1524 by checking if your version of Mort Bay Jetty is below 6.1.17 and testing for XSS vulnerabilities in directory listings.