Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.59976
Categoría:FreeBSD Local Security Checks
Título:FreeBSD Ports: jetty
Resumen:The remote host is missing an update to the system; as announced in the referenced advisory.
Descripción:Summary:
The remote host is missing an update to the system
as announced in the referenced advisory.

Vulnerability Insight:
The following package is affected: jetty

CVE-2007-5613
Cross-site scripting (XSS) vulnerability in Dump Servlet in Mortbay
Jetty before 6.1.6rc1 allows remote attackers to inject arbitrary web
script or HTML via unspecified parameters and cookies.

CVE-2007-5614
Mortbay Jetty before 6.1.6rc1 does not properly handle 'certain quote
sequences' in HTML cookie parameters, which allows remote attackers to
hijack browser sessions via unspecified vectors.

CVE-2007-5615
CRLF injection vulnerability in Mortbay Jetty before 6.1.6rc0 allows
remote attackers to inject arbitrary HTTP headers and conduct HTTP
response splitting attacks via unspecified vectors.

Solution:
Update your system with the appropriate patches or
software upgrades.

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2007-5613
BugTraq ID: 26697
http://www.securityfocus.com/bid/26697
CERT/CC vulnerability note: VU#237888
http://www.kb.cert.org/vuls/id/237888
https://www.redhat.com/archives/fedora-package-announce/2008-July/msg00227.html
https://www.redhat.com/archives/fedora-package-announce/2008-July/msg00250.html
http://osvdb.org/42497
http://secunia.com/advisories/27925
http://secunia.com/advisories/30941
http://secunia.com/advisories/35143
SuSE Security Announcement: SUSE-SR:2009:004 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00002.html
Common Vulnerability Exposure (CVE) ID: CVE-2007-5614
BugTraq ID: 26695
http://www.securityfocus.com/bid/26695
CERT/CC vulnerability note: VU#438616
http://www.kb.cert.org/vuls/id/438616
http://osvdb.org/42496
Common Vulnerability Exposure (CVE) ID: CVE-2007-5615
BugTraq ID: 26696
http://www.securityfocus.com/bid/26696
CERT/CC vulnerability note: VU#212984
http://www.kb.cert.org/vuls/id/212984
http://osvdb.org/42495
CopyrightCopyright (C) 2008 E-Soft Inc.

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.