Maven package
org.apache.geronimo.plugins/console
pkg:maven/org.apache.geronimo.plugins/console
Vulnerabilities (3)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2009-0039 | — | < 2.1.4 | 2.1.4 | Apr 17, 2009 | Multiple cross-site request forgery (CSRF) vulnerabilities in the web administration console in Apache Geronimo Application Server 2.1 through 2.1.3 allow remote attackers to hijack the authentication of administrators for requests that (1) change the web administration password, | ||
| CVE-2009-0038 | — | >= 2.1.0, < 2.1.4 | 2.1.4 | Apr 17, 2009 | Multiple cross-site scripting (XSS) vulnerabilities in the web administration console in Apache Geronimo Application Server 2.1 through 2.1.3 allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) ip, (3) username, or (4) description parameter to cons | ||
| CVE-2008-5518 | — | >= 2.1.0, < 2.1.4 | 2.1.4 | Apr 17, 2009 | Multiple directory traversal vulnerabilities in the web administration console in Apache Geronimo Application Server 2.1 through 2.1.3 on Windows allow remote attackers to upload files to arbitrary directories via directory traversal sequences in the (1) group, (2) artifact, (3) |
- CVE-2009-0039Apr 17, 2009affected < 2.1.4fixed 2.1.4
Multiple cross-site request forgery (CSRF) vulnerabilities in the web administration console in Apache Geronimo Application Server 2.1 through 2.1.3 allow remote attackers to hijack the authentication of administrators for requests that (1) change the web administration password,
- CVE-2009-0038Apr 17, 2009affected >= 2.1.0, < 2.1.4fixed 2.1.4
Multiple cross-site scripting (XSS) vulnerabilities in the web administration console in Apache Geronimo Application Server 2.1 through 2.1.3 allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) ip, (3) username, or (4) description parameter to cons
- CVE-2008-5518Apr 17, 2009affected >= 2.1.0, < 2.1.4fixed 2.1.4
Multiple directory traversal vulnerabilities in the web administration console in Apache Geronimo Application Server 2.1 through 2.1.3 on Windows allow remote attackers to upload files to arbitrary directories via directory traversal sequences in the (1) group, (2) artifact, (3)