Required CVE Record Information
Description
Cross-site scripting (XSS) vulnerability in Mayaa before 1.1.23 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving the default error page for the org.seasar.mayaa.impl.engine.PageNotFoundException exception and possibly other exceptions.
References 7 Total
- exchange.xforce.ibmcloud.com: mayaa-errorpage-xss(47623) vdb-entry
- secunia.com: 33333 third-party-advisory
- securityfocus.com: 33015 vdb-entry
- osvdb.org: 51007 vdb-entry
- jvndb.jvn.jp: JVNDB-2008-000085 third-party-advisory
- http://mayaa.seasar.org/news/vulnerability20081225.html
- jvn.jp: JVN#17298485 third-party-advisory
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 7 Total
- exchange.xforce.ibmcloud.com: mayaa-errorpage-xss(47623) vdb-entryx_transferred
- secunia.com: 33333 third-party-advisoryx_transferred
- securityfocus.com: 33015 vdb-entryx_transferred
- osvdb.org: 51007 vdb-entryx_transferred
- jvndb.jvn.jp: JVNDB-2008-000085 third-party-advisoryx_transferred
- http://mayaa.seasar.org/news/vulnerability20081225.html x_transferred
- jvn.jp: JVN#17298485 third-party-advisoryx_transferred