Sun Java system Glassfish Glassfish... CVE-2008-2751 CNNVD-200806-251 CNNVD-200811-432

4.3 AV AC AU C I A
发布: 2008-06-18
修订: 2018-10-11

Sun Java System 应用程序服务器9.1_01版本中的Glassfish webadmin界面存在多个跨站脚本漏洞。远程攻击者可以借助到(a)resourceNode/customResourceNew.jsf的(1)propertyForm:propertyContentPage:propertySheet:propertSectionTextField:jndiProp:JndiNew,(2)propertyForm:propertyContentPage:propertySheet:propertSectionTextField:resTypeProp:resType,(3)propertyForm:propertyContentPage:propertySheet:propertSectionTextField:factoryClassProp:factoryClass,或(4)propertyForm:propertyContentPage:propertySheet:propertSectionTextField:descProp:desc参数;到(b)resourceNode/externalResourceNew.jsfthe的(5)propertyForm:propertyContentPage:propertySheet:propertSectionTextField:jndiProp:JndiNew,(6)propertyForm:propertyContentPage:propertySheet:propertSectionTextField:resTypeProp:resType,(7)propertyForm:propertyContentPage:propertySheet:propertSectionTextField:factoryClassProp:factoryClass,(8)propertyForm:propertyContentPage:propertySheet:propertSectionTextField:jndiLookupProp:jndiLookup,或(9)...

0%
当前有11条漏洞利用/PoC
当前有9条受影响产品信息