~ubuntu-security/ubuntu-cve-tracker/master

« back to all changes in this revision

Viewing changes to retired/CVE-2013-6235

  • Committer: Steve Beattie
  • Date: 2019-02-19 06:18:27 UTC
  • Revision ID: sbeattie@ubuntu.com-20190219061827-oh57fzcfc1u9dlfk
The ubuntu-cve-tracker project has been converted to git.

Please use 'git clone https://git.launchpad.net/ubuntu-cve-tracker' to
get the converted tree.

Show diffs side-by-side

added added

removed removed

Lines of Context:
1
 
Candidate: CVE-2013-6235
2
 
PublicDate: 2014-01-31
3
 
References:
4
 
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6235
5
 
 http://seclists.org/bugtraq/2014/Jan/92
6
 
Description:
7
 
 Multiple cross-site scripting (XSS) vulnerabilities in JAMon (Java
8
 
 Application Monitor) 2.7 and earlier allow remote attackers to inject
9
 
 arbitrary web script or HTML via the (1) listenertype or (2)
10
 
 currentlistener parameter to mondetail.jsp or ArraySQL parameter to (3)
11
 
 mondetail.jsp, (4) jamonadmin.jsp, (5) sql.jsp, or (6) exceptions.jsp.
12
 
Ubuntu-Description:
13
 
Notes:
14
 
 jamon.war/JAMon web apps gets excluded by debian/orig-tar.sh
15
 
Bugs:
16
 
Priority: medium
17
 
Discovered-by:
18
 
Assigned-to:
19
 
 
20
 
Patches_libjamon-java:
21
 
upstream_libjamon-java: needs-triage
22
 
lucid_libjamon-java: ignored (reached end-of-life)
23
 
precise_libjamon-java: not-affected
24
 
quantal_libjamon-java: not-affected
25
 
saucy_libjamon-java: not-affected
26
 
devel_libjamon-java: not-affected