First published: Wed Oct 07 2009(Updated: )
Cross-site scripting (XSS) vulnerability in the CookieDump.java sample application in Mort Bay Jetty 6.1.19 and 6.1.20 allows remote attackers to inject arbitrary web script or HTML via the Value parameter in a GET request to cookie/.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Eclipse Jetty | =6.1.20 | |
Eclipse Jetty | =6.1.19 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-3579 is classified as a medium severity cross-site scripting (XSS) vulnerability.
To fix CVE-2009-3579, upgrade your Jetty installation to version 6.1.21 or later.
CVE-2009-3579 affects Mort Bay Jetty versions 6.1.19 and 6.1.20.
Yes, CVE-2009-3579 can be exploited remotely by injecting malicious scripts via the Value parameter in HTTP GET requests.
Exploiting CVE-2009-3579 can lead to unauthorized access to user information and the potential for session hijacking.