CVE Vulnerabilities

CVE-2007-5614

Published: Dec 05, 2007 | Modified: Jun 10, 2009
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Mortbay Jetty before 6.1.6rc1 does not properly handle certain quote sequences in HTML cookie parameters, which allows remote attackers to hijack browser sessions via unspecified vectors.

Affected Software

Name Vendor Start Version End Version
Jetty Mortbay_jetty 1.0 (including) 1.0 (including)
Jetty Mortbay_jetty 2.4 (including) 2.4 (including)
Jetty Mortbay_jetty 3.0 (including) 3.0 (including)
Jetty Mortbay_jetty 3.1 (including) 3.1 (including)
Jetty Mortbay_jetty 4.0 (including) 4.0 (including)
Jetty Mortbay_jetty 4.1 (including) 4.1 (including)
Jetty Mortbay_jetty 4.2 (including) 4.2 (including)
Jetty Mortbay_jetty 5 (including) 5 (including)
Jetty Mortbay_jetty 5.1 (including) 5.1 (including)
Jetty Mortbay_jetty 6 (including) 6 (including)
Jetty Mortbay_jetty 6.1 (including) 6.1 (including)

References