Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2008-5266

Severity
4.3MEDIUM
EPSS
1.1%
top 21.66%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedNov 28
Latest updateMay 14

Description

Cross-site scripting (XSS) vulnerability in configuration/httpListenerEdit.jsf in the GlassFish 2 UR2 b04 webadmin interface in Sun Java System Application Server 9.1_01 build b09d-fcs and 9.1_02 build b04-fcs allows remote attackers to inject arbitrary web script or HTML via the name parameter, a different vector than CVE-2008-2751.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages2 packages

🔴Vulnerability Details

3
GHSA
GHSA-qq4x-fwvx-7q2h: Cross-site scripting (XSS) vulnerability in configuration/httpListenerEdit2022-05-14
CVEList
CVE-2008-5266: Cross-site scripting (XSS) vulnerability in configuration/httpListenerEdit2008-11-28
OSV
CVE-2008-5266: Cross-site scripting (XSS) vulnerability in configuration/httpListenerEdit2008-11-28

💥Exploits & PoCs

2
Exploit-DB
GOM Player 2.3.10.5266 - '.fpx' Denial of Service2017-02-15
Exploit-DB
Sun GlassFish 2.1 - 'name' Cross-Site Scripting2008-06-10
CVE-2008-5266 (MEDIUM CVSS 4.3) | Cross-site scripting (XSS) vulnerab | cvebase.io