CVE-2009-3579: XSS
Published Oct 7, 2009
·Updated
Cross-site scripting (XSS) vulnerability in the CookieDump.java sample application in Mort Bay Jetty 6.1.19 and 6.1.20 allows remote attackers to inject arbitrary web script or HTML via the Value parameter in a GET request to cookie/.
Affected Software
2 affected components
Mortbay Jetty=6.1.20
Mortbay Jetty=6.1.19
Event History
Oct 7, 2009
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2009-3579?
CVE-2009-3579 is classified as a medium severity cross-site scripting (XSS) vulnerability.
2
How do I fix CVE-2009-3579?
To fix CVE-2009-3579, upgrade your Jetty installation to version 6.1.21 or later.
3
What are the affected software versions for CVE-2009-3579?
CVE-2009-3579 affects Mort Bay Jetty versions 6.1.19 and 6.1.20.
4
Can CVE-2009-3579 be exploited remotely?
Yes, CVE-2009-3579 can be exploited remotely by injecting malicious scripts via the Value parameter in HTTP GET requests.
5
What is the impact of exploiting CVE-2009-3579?
Exploiting CVE-2009-3579 can lead to unauthorized access to user information and the potential for session hijacking.