Cross-Site Scripting Vulnerabilities in Apache Jackrabbit
CVE-2009-0026
Currently unrated
What is CVE-2009-0026?
Apache Jackrabbit, prior to version 1.5.2, is vulnerable to multiple cross-site scripting (XSS) issues. Remote attackers can exploit these vulnerabilities by injecting arbitrary web scripts or HTML through the 'q' parameter in 'search.jsp' and 'swr.jsp'. This can lead to unauthorized actions being performed on behalf of users and exposure of sensitive data.