Sploitus

CVE-2008-5266

1 known exploit for CVE-2008-5266

Cross-site scripting (XSS) vulnerability in configuration/httpListenerEdit.jsf in the GlassFish 2 UR2 b04 webadmin interface in Sun Java System Application Server 9.1_01 build b09d-fcs and 9.1_02 build b04-fcs allows remote attackers to inject arbitrary web script or HTML via the name parameter, a different vector than CVE-2008-2751.

Sun Java System Application Server
= 9.1_01, 9.1_02
Oracle Glassfish Server
= 2.0
CVSS 2.0
4.3 MEDIUM
EPSS
4.9% (91th percentile)
Weakness
CWE-79
NVD status
Modified
Published
2008-11-28
CVE-2008-5266 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2008-5266

Proof-of-concept code and exploit modules indexed by Sploitus