Page 3 of 11 results (0.003 seconds)

CVSS: 4.3EPSS: 0%CPEs: 1EXPL: 5

Multiple cross-site scripting (XSS) vulnerabilities in Apache Geronimo 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) time parameter to cal2.jsp and (2) any invalid parameter, which causes an XSS when the log file is viewed by the Web-Access-Log viewer. • https://www.exploit-db.com/exploits/27096 https://www.exploit-db.com/exploits/27095 http://issues.apache.org/jira/browse/GERONIMO-1474 http://rhn.redhat.com/errata/RHSA-2008-0630.html http://secunia.com/advisories/18485 http://secunia.com/advisories/31493 http://www.oliverkarow.de/research/geronimo_css.txt http://www.redhat.com/support/errata/RHSA-2008-0261.html http://www.securityfocus.com/archive/1/421996/100/0/threaded http://www.securityfocus.com/bid/16260 http: • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •