Description
Multiple cross-site scripting (XSS) vulnerabilities in JAMon (Java Application Monitor) 2.7 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) listenertype or (2) currentlistener parameter to mondetail.jsp or ArraySQL parameter to (3) mondetail.jsp, (4) jamonadmin.jsp, (5) sql.jsp, or (6) exceptions.jsp.
Remediation
References
http://osvdb.org/102570
http://osvdb.org/102571
http://osvdb.org/102572
http://osvdb.org/102573
http://packetstormsecurity.com/files/124933
http://seclists.org/fulldisclosure/2014/Jan/164
http://www.securityfocus.com/archive/1/530877/100/0/threaded
https://exchange.xforce.ibmcloud.com/vulnerabilities/90699
Related Vulnerabilities
CVE-2021-44906 Vulnerability in maven package org.webjars.bowergithub.substack:minimist
CVE-2016-10735 Vulnerability in maven package ua.mobius.media:bootstrap
CVE-2023-29511 Vulnerability in maven package org.xwiki.platform:xwiki-platform-administration-ui
CVE-2011-4367 Vulnerability in maven package org.apache.myfaces.core:myfaces-core-project
CVE-2023-37754 Vulnerability in maven package tech.powerjob:powerjob-common