VYPR

Maven package

org.apache.geronimo.plugins/console

pkg:maven/org.apache.geronimo.plugins/console

Vulnerabilities (3)

  • CVE-2009-0039Apr 17, 2009
    affected < 2.1.4fixed 2.1.4

    Multiple cross-site request forgery (CSRF) vulnerabilities in the web administration console in Apache Geronimo Application Server 2.1 through 2.1.3 allow remote attackers to hijack the authentication of administrators for requests that (1) change the web administration password,

  • CVE-2009-0038Apr 17, 2009
    affected >= 2.1.0, < 2.1.4fixed 2.1.4

    Multiple cross-site scripting (XSS) vulnerabilities in the web administration console in Apache Geronimo Application Server 2.1 through 2.1.3 allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) ip, (3) username, or (4) description parameter to cons

  • CVE-2008-5518Apr 17, 2009
    affected >= 2.1.0, < 2.1.4fixed 2.1.4

    Multiple directory traversal vulnerabilities in the web administration console in Apache Geronimo Application Server 2.1 through 2.1.3 on Windows allow remote attackers to upload files to arbitrary directories via directory traversal sequences in the (1) group, (2) artifact, (3)