Bug#454529: two more CVEs

2007-12-19 Thread Michael Koch
On Wed, Dec 05, 2007 at 11:45:41PM +0100, Steffen Joeris wrote: > Hi > > There have been two more CVEs[0][1] for jetty: > > CVE-2007-5613: > > Cross-site scripting (XSS) vulnerability in Dump Servlet in Mortbay Jetty > before 6.1.6rc1 allows remote attackers to inject arbitrary web script or >

Bug#454529: two more CVEs

2007-12-05 Thread Steffen Joeris
Hi There have been two more CVEs[0][1] for jetty: CVE-2007-5613: Cross-site scripting (XSS) vulnerability in Dump Servlet in Mortbay Jetty before 6.1.6rc1 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters and cookies. CVE-2007-5614: Mortbay Jetty befo