Description
Multiple cross-site scripting (XSS) vulnerabilities in JAMon (Java Application Monitor) 2.7 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) listenertype or (2) currentlistener parameter to mondetail.jsp or ArraySQL parameter to (3) mondetail.jsp, (4) jamonadmin.jsp, (5) sql.jsp, or (6) exceptions.jsp.
Remediation
References
http://osvdb.org/102570
http://osvdb.org/102571
http://osvdb.org/102572
http://osvdb.org/102573
http://packetstormsecurity.com/files/124933
http://seclists.org/fulldisclosure/2014/Jan/164
http://www.securityfocus.com/archive/1/530877/100/0/threaded
https://exchange.xforce.ibmcloud.com/vulnerabilities/90699
Related Vulnerabilities
CVE-2022-3783 Vulnerability in npm package node-red-dashboard
CVE-2018-14042 Vulnerability in maven package org.webjars.bowergithub.angular-ui:bootstrap
CVE-2022-41404 Vulnerability in maven package org.ini4j:ini4j
CVE-2015-0250 Vulnerability in maven package batik:batik-dom
CVE-2023-39015 Vulnerability in maven package us.codecraft:webmagic-extension