Vulnerabilities (CVE)

Filtered by vendor Mortbay Jetty Subscribe
Filtered by product Jetty
Total 4 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2007-5613 1 Mortbay Jetty 1 Jetty 2023-12-10 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in Dump Servlet in Mortbay Jetty before 6.1.6rc1 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters and cookies.
CVE-2007-5615 1 Mortbay Jetty 1 Jetty 2023-12-10 5.0 MEDIUM N/A
CRLF injection vulnerability in Mortbay Jetty before 6.1.6rc0 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.
CVE-2007-6672 1 Mortbay Jetty 1 Jetty 2023-12-10 5.0 MEDIUM N/A
Mortbay Jetty 6.1.5 and 6.1.6 allows remote attackers to bypass protection mechanisms and read the source of files via multiple '/' (slash) characters in the URI.
CVE-2007-5614 1 Mortbay Jetty 1 Jetty 2023-12-10 7.5 HIGH N/A
Mortbay Jetty before 6.1.6rc1 does not properly handle "certain quote sequences" in HTML cookie parameters, which allows remote attackers to hijack browser sessions via unspecified vectors.