VYPR
Moderate severityNVD Advisory· Published Mar 31, 2003· Updated Apr 16, 2026

CVE-2002-1533

CVE-2002-1533

Description

Cross-site scripting (XSS) vulnerability in Jetty JSP servlet engine allows remote attackers to insert arbitrary HTML or script via an HTTP request to a .jsp file whose name contains the malicious script and some encoded linefeed characters (%0a).

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.mortbay.jetty:jettyMaven
< 4.1.14.1.1

Affected products

1
  • cpe:2.3:a:jetty:jetty:4.1.0_rc4:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

8

News mentions

0

No linked articles in our index yet.