CVE-2008-5266
published 2008-11-28CVE-2008-5266: Cross-site scripting (XSS) vulnerability in configuration/httpListenerEdit.jsf in the GlassFish 2 UR2 b04 webadmin interface in Sun Java System Application…
PriorityP425medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EXPLOIT
EPSS
4.89%
91.1th percentile
Cross-site scripting (XSS) vulnerability in configuration/httpListenerEdit.jsf in the GlassFish 2 UR2 b04 webadmin interface in Sun Java System Application Server 9.1_01 build b09d-fcs and 9.1_02 build b04-fcs allows remote attackers to inject arbitrary web script or HTML via the name parameter, a different vector than CVE-2008-2751.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | glassfish_server | — | — |
| sun | java_system_application_server | — | — |
| sun | java_system_application_server | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qq4x-fwvx-7q2h: Cross-site scripting (XSS) vulnerability in configuration/httpListenerEdit
ghsa_unreviewed·2022-05-14·CVSS 4.3
CVE-2008-5266 [MEDIUM] CWE-79 GHSA-qq4x-fwvx-7q2h: Cross-site scripting (XSS) vulnerability in configuration/httpListenerEdit
Cross-site scripting (XSS) vulnerability in configuration/httpListenerEdit.jsf in the GlassFish 2 UR2 b04 webadmin interface in Sun Java System Application Server 9.1_01 build b09d-fcs and 9.1_02 build b04-fcs allows remote attackers to inject arbitrary web script or HTML via the name parameter, a different vector than CVE-2008-2751.
OSV
CVE-2008-5266: Cross-site scripting (XSS) vulnerability in configuration/httpListenerEdit
osv·2008-11-28·CVSS 4.3
CVE-2008-5266 [MEDIUM] CVE-2008-5266: Cross-site scripting (XSS) vulnerability in configuration/httpListenerEdit
Cross-site scripting (XSS) vulnerability in configuration/httpListenerEdit.jsf in the GlassFish 2 UR2 b04 webadmin interface in Sun Java System Application Server 9.1_01 build b09d-fcs and 9.1_02 build b04-fcs allows remote attackers to inject arbitrary web script or HTML via the name parameter, a different vector than CVE-2008-2751.
No detection rules found.
Exploit-DB
GOM Player 2.3.10.5266 - '.fpx' Denial of Service
exploitdb·2017-02-15·CVSS 7.8
CVE-2017-5881 [HIGH] GOM Player 2.3.10.5266 - '.fpx' Denial of Service
GOM Player 2.3.10.5266 - '.fpx' Denial of Service
---
# Exploit Title: GOM Player 2.3.10.5266 - Remote heap corruption (.fpx)
# Date: 2017-02-15
# Exploit Author: Peter Baris
# Exploit link: http://www.saptech-erp.com.au/resources/PoC.zip
# Software Link: http://player.gomlab.com/download.gom?language=eng
# CVE: CVE-2017-5881
# Version: 2.3.10.5266
# Tested on: Windows Server 2008 R2 x64, Windows 7 SP1 x64
POC:
https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/41367.zip
Open the malicious fpx file with CTRL+U, served by a webserver:
WinDbg
(864.150): Access violation - code c0000005 (first chance)
First chance exceptions are reported before any exception handling.
This exception may be expected and handled.
eax=092fcde8 ebx=00000000 ecx=41414141 edx
Exploit-DB
Sun GlassFish 2.1 - 'name' Cross-Site Scripting
exploitdb·2008-06-10
CVE-2008-5266 Sun GlassFish 2.1 - 'name' Cross-Site Scripting
Sun GlassFish 2.1 - 'name' Cross-Site Scripting
---
source: https://www.securityfocus.com/bid/29646/info
Sun Glassfish is prone to a cross-site scripting vulnerability because the application fails to sufficiently sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may let the attacker steal cookie-based authentication credentials and launch other attacks.
http://www.example.com/configuration/httpListenerEdit.jsf?name=&configName=server-config
No writeups or analysis indexed.
http://secunia.com/advisories/30604http://securityreason.com/securityalert/4659http://webappsecurity.wordpress.com/2008/06/11/xss-glassfish-web-admin-interface-sun-java-system-application/http://www.securityfocus.com/archive/1/493243/100/0/threadedhttp://www.securityfocus.com/bid/29646https://exchange.xforce.ibmcloud.com/vulnerabilities/47029http://secunia.com/advisories/30604http://securityreason.com/securityalert/4659http://webappsecurity.wordpress.com/2008/06/11/xss-glassfish-web-admin-interface-sun-java-system-application/http://www.securityfocus.com/archive/1/493243/100/0/threadedhttp://www.securityfocus.com/bid/29646https://exchange.xforce.ibmcloud.com/vulnerabilities/47029
2008-11-28
Published