CVE-2009-0038 EXPLOIT
4.3
MEDIUM · CVSS 2.0 · EPSS 18% (pctl 97)
Patch early
A public exploit exists.
Description
Multiple cross-site scripting (XSS) vulnerabilities in the web administration console in Apache Geronimo Application Server 2.1 through 2.1.3 allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) ip, (3) username, or (4) description parameter to console/portal/Server/Monitoring; or (5) the PATH_INFO to the default URI under console/portal/.
Scoring
| CVSS | 4.3 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
| EPSS | 18% — more likely to be exploited than 97% of all CVEs |
| Weakness | CWE-79 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2009-04-17 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| apache | geronimo |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Apache Geronimo 2.1.x - '/console/portal/Server/Monitoring' Multiple Cross-Site Scripting Vulnerabilities | 2009-04-16 |
| exploit-db | Apache Geronimo 2.1.x - '/console/portal/' URI Cross-Site Scripting | 2009-04-16 |
References
- http://dsecrg.com/pages/vul/show.php?id=119
- http://geronimo.apache.org/21x-security-report.html#2.1.xSecurityReport-214
- http://issues.apache.org/jira/browse/GERONIMO-4597
- http://secunia.com/advisories/34715
- http://www.securityfocus.com/archive/1/502734/100/0/threaded
- http://www.securityfocus.com/bid/34562
- http://www.vupen.com/english/advisories/2009/1089
- http://dsecrg.com/pages/vul/show.php?id=119
- http://geronimo.apache.org/21x-security-report.html#2.1.xSecurityReport-214
- http://issues.apache.org/jira/browse/GERONIMO-4597
- http://secunia.com/advisories/34715
- http://www.securityfocus.com/archive/1/502734/100/0/threaded
- http://www.securityfocus.com/bid/34562
- http://www.vupen.com/english/advisories/2009/1089
→ the Explorer · watch your stack · NVD