JAMon(Java Application Monitor)是一款免费、简单、高性能、线程安全的Java应用程序监视器。 JAMon 2.7及之前的版本中存在多个跨站脚本漏洞,这些漏洞源于mondetail.jsp脚本没有正确过滤‘listenertype’和‘currentlistener’参数;mondetail.jsp脚本、jamonadmin.jsp脚本、sql.jsp脚本及exceptions.jsp脚本没有正确过滤‘ArraySQL’参数。远程攻击者可利用这些漏洞注入任意Web脚本或HTML
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2014-0001 | Oracle MySQL和MariaDB 缓冲区错误漏洞 | |
| CVE-2013-6143 | Schneider Electric Telvent SAGE 3030 RTU 远程拒绝服务漏洞 | |
| CVE-2013-4383 | Drupal jQuery Countdown模块HTML注入漏洞 | |
| CVE-2013-4979 | IdeaMK EPS Viewer 远程缓冲区溢出漏洞 | |
| CVE-2014-1204 | Tableau Server SQL注入漏洞 | |
| CVE-2013-6727 | IBM Sametime Connect客户端信息泄露漏洞 |
No comments yet