CVE-2002-1533

EPSS 5.2%

Jetty Javascript Inclusion Vulnerability

發布日:2022/4/30修改日:2024/11/28

描述

Cross-site scripting (XSS) vulnerability in Jetty JSP servlet engine allows remote attackers to insert arbitrary HTML or script via an HTTP request to a .jsp file whose name contains the malicious script and some encoded linefeed characters (`%0a`).

受影響套件(1)

參考連結(4)