vendor:
GlassFish Server
by:
Roberto Suggi Liverani
7,5
CVSS
HIGH
Cross Site Scripting
79
CWE
Product Name: GlassFish Server
Affected Version From: Oracle GlassFish Server 3.1.1 (build 12)
Affected Version To: Oracle GlassFish Server 3.1.1 (build 12)
Patch Exists: YES
Related CWE: CVE 2012-0551
CPE: a:oracle:glassfish_server:3.1.1
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: All
2012
Oracle GlassFish Server Multiple XSS
Security-Assessment.com has discovered that components of the Oracle GlassFish Server administrative web interface are vulnerable to both reflected and stored Cross Site Scripting attacks. All pages where Cross Site Scripting vulnerabilities were discovered require authentication. Reflected Cross Site Scripting was discovered in multiple parts of the application, while Stored Cross Site Scripting was detected in the /management/domain/create-password-alias page.
Mitigation:
Ensure that user input is properly sanitized and validated before being used in the application.