Unrated severityNVD Advisory· Published May 6, 2009· Updated Apr 23, 2026
CVE-2009-1554
CVE-2009-1554
Description
Cross-site scripting (XSS) vulnerability in ThemeServlet.java in Sun Woodstock 4.2, as used in Sun GlassFish Enterprise Server and other products, allows remote attackers to inject arbitrary web script or HTML via a UTF-7 string in the PATH_INFO, which is displayed on the 404 error page, as demonstrated by the PATH_INFO to theme/META-INF.
Affected products
1- cpe:2.3:a:sun:woodstock:4.2:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
9- woodstock.dev.java.net/servlets/ReadMsgnvdPatchVendor Advisory
- dsecrg.com/pages/vul/show.phpnvdExploit
- www.nabble.com/-DSECRG--Sun-Glassfish-Multiple-Security-Vulnerabilities-p22595435.htmlnvdExploit
- www.securityfocus.com/bid/34829nvdExploit
- osvdb.org/54220nvd
- secunia.com/advisories/35006nvd
- www.nabble.com/Re:--DSECRG--Sun-Glassfish-Multiple-Security-Vulnerabilities-p23002524.htmlnvd
- www.securityfocus.com/archive/1/503239/100/0/threadednvd
- exchange.xforce.ibmcloud.com/vulnerabilities/50336nvd
News mentions
0No linked articles in our index yet.