Mortbay Jetty 6.1.21

CPE Details

Mortbay Jetty 6.1.21
6.1.21
2010-01-14
16h49 +00:00
2011-08-16
13h00 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:mortbay:jetty:6.1.21:*:*:*:*:*:*:*

Informations

Vendor

mortbay

Product

jetty

Version

6.1.21

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2009-5049 2019-11-06 17h46 +00:00 WebApp JSP Snoop page XSS in jetty though 6.1.21.
6.1
Medium
CVE-2011-4461 2011-12-30 00h00 +00:00 Jetty 8.1.0.RC2 and earlier computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters.
5.3
Medium
CVE-2009-4612 2010-01-13 20h00 +00:00 Multiple cross-site scripting (XSS) vulnerabilities in the WebApp JSP Snoop page in Mort Bay Jetty 6.1.x through 6.1.21 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the default URI under (1) jspsnoop/, (2) jspsnoop/ERROR/, and (3) jspsnoop/IOException/, and possibly the PATH_INFO to (4) snoop.jsp.
4.3