VendorsMortbayjetty6.1.21
Vulnerabilities

Mortbay Jetty 6.1.21

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2011-4461
Jetty 8.1.0.RC2 and earlier computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters.
Published 2011-12-30 · Modified
5.3EPSS 0.049
CVE-2009-4612
Multiple cross-site scripting (XSS) vulnerabilities in the WebApp JSP Snoop page in Mort Bay Jetty 6.1.x through 6.1.21 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the default URI under (1) jspsnoop/, (2) jspsnoop/ERROR/, and (3) jspsnoop/IOException/, and possibly the PATH_INFO to (4) snoop.jsp.
Published 2010-01-13 · Modified
4.31 PoCEPSS 0.033