Vulnerability Name:

CVE-2009-1428 (CCN-50170)

Assigned:2009-04-28
Published:2009-04-28
Updated:2017-08-17
Summary:Multiple cross-site scripting (XSS) vulnerabilities in ccLgView.exe in the Symantec Log Viewer, as used in Symantec AntiVirus (SAV) before 10.1 MR8, Symantec Endpoint Protection (SEP) 11.0 before 11.0 MR1, Norton 360 1.0, and Norton Internet Security 2005 through 2008, allow remote attackers to inject arbitrary web script or HTML via a crafted e-mail message, related to "two parsing errors."
CVSS v3 Severity:5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): Low
Availibility (A): None
CVSS v2 Severity:4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N)
3.6 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:UR)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
4.3 Medium (CCN CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N)
3.6 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:UR)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
Vulnerability Type:CWE-79
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2009-1428

Source: OSVDB
Type: UNKNOWN
54132

Source: CCN
Type: SA34936
Symantec Log Viewer Script Insertion Vulnerabilities

Source: SECUNIA
Type: UNKNOWN
34936

Source: CCN
Type: SECTRACK ID: 1022133
Norton Internet Security Input Validation Flaw in Log Viewer Permits Remote HTML Injection Attacks

Source: CCN
Type: SECTRACK ID: 1022134
Symantec Anti Virus Input Validation Flaw in Log Viewer Permits Remote HTML Injection Attacks

Source: CCN
Type: SECTRACK ID: 1022135
Symantec Endpoint Protection Input Validation Flaw in Log Viewer Permits Remote HTML Injection Attacks

Source: CCN
Type: OSVDB ID: 54132
Symantec Log Viewer ccLgView.exe Email Filtering Statistics XSS

Source: BID
Type: UNKNOWN
34669

Source: CCN
Type: BID-34669
Multiple Symantec Products Log Viewer Multiple Script Injection Vulnerabilities

Source: SECTRACK
Type: UNKNOWN
1022133

Source: SECTRACK
Type: UNKNOWN
1022134

Source: SECTRACK
Type: UNKNOWN
1022135

Source: CCN
Type: SYM09-006
Symantec Log Viewer JavaScript Injection Vulnerabilities

Source: CONFIRM
Type: UNKNOWN
http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2009&suid=20090428_01

Source: VUPEN
Type: UNKNOWN
ADV-2009-1203

Source: XF
Type: UNKNOWN
multiple-symantec-log-xss(50170)

Source: XF
Type: UNKNOWN
multiple-symantec-log-xss(50170)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:symantec:antivirus:10.0:*:*:*:*:*:*:*
  • OR cpe:/a:symantec:antivirus:10.0.1:*:*:*:*:*:*:*
  • OR cpe:/a:symantec:antivirus:10.0.1.1:*:*:*:*:*:*:*
  • OR cpe:/a:symantec:antivirus:10.0.2:*:*:*:*:*:*:*
  • OR cpe:/a:symantec:antivirus:10.0.2.1:*:*:*:*:*:*:*
  • OR cpe:/a:symantec:antivirus:10.0.2.2:*:*:*:*:*:*:*
  • OR cpe:/a:symantec:antivirus:10.0.3:*:*:*:*:*:*:*
  • OR cpe:/a:symantec:antivirus:10.0.4:*:*:*:*:*:*:*
  • OR cpe:/a:symantec:antivirus:10.0.5:*:*:*:*:*:*:*
  • OR cpe:/a:symantec:antivirus:10.0.6:*:*:*:*:*:*:*
  • OR cpe:/a:symantec:antivirus:10.0.7:*:*:*:*:*:*:*
  • OR cpe:/a:symantec:antivirus:10.0.8:*:*:*:*:*:*:*
  • OR cpe:/a:symantec:antivirus:10.0.9:*:*:*:*:*:*:*
  • OR cpe:/a:symantec:antivirus:*:*:*:*:*:*:*:* (Version <= 10.1)
  • OR cpe:/a:symantec:endpoint_protection:11.0:*:*:*:*:*:*:*
  • OR cpe:/a:symantec:norton_360:1.0:*:*:*:*:*:*:*
  • OR cpe:/a:symantec:norton_internet_security:2005:*:anti_spyware:*:*:*:*:*
  • OR cpe:/a:symantec:norton_internet_security:2005:*:professional:*:*:*:*:*
  • OR cpe:/a:symantec:norton_internet_security:2005:11.0:*:*:*:*:*:*
  • OR cpe:/a:symantec:norton_internet_security:2005:11.0.9:*:*:*:*:*:*
  • OR cpe:/a:symantec:norton_internet_security:2005:11.5.6.14:*:*:*:*:*:*
  • OR cpe:/a:symantec:norton_internet_security:2005_contains_nav_11.0.0:*:*:*:*:*:*:*
  • OR cpe:/a:symantec:norton_internet_security:2006:*:*:*:*:*:*:*
  • OR cpe:/a:symantec:norton_internet_security:2006:*:professional:*:*:*:*:*
  • OR cpe:/a:symantec:norton_internet_security:2007:*:*:*:*:*:*:*
  • OR cpe:/a:symantec:norton_internet_security:2008:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:symantec:norton_internet_security:2005:*:*:*:*:*:*:*
  • OR cpe:/a:symantec:norton_internet_security:2006:*:*:*:*:*:*:*
  • OR cpe:/a:symantec:norton_360:1.0:*:*:*:*:*:*:*
  • OR cpe:/a:symantec:norton_internet_security:2007:*:*:*:*:*:*:*
  • OR cpe:/a:symantec:norton_internet_security:2008:*:*:*:*:*:*:*
  • OR cpe:/a:symantec:norton_internet_security:2005::professional:*:*:*:*:*
  • OR cpe:/a:symantec:norton_internet_security:2006::professional:*:*:*:*:*
  • OR cpe:/a:symantec:antivirus:10.1::corporate:*:*:*:*:*
  • OR cpe:/a:symantec:endpoint_protection:11.0.6200.754:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    symantec antivirus 10.0
    symantec antivirus 10.0.1
    symantec antivirus 10.0.1.1
    symantec antivirus 10.0.2
    symantec antivirus 10.0.2.1
    symantec antivirus 10.0.2.2
    symantec antivirus 10.0.3
    symantec antivirus 10.0.4
    symantec antivirus 10.0.5
    symantec antivirus 10.0.6
    symantec antivirus 10.0.7
    symantec antivirus 10.0.8
    symantec antivirus 10.0.9
    symantec antivirus *
    symantec endpoint protection 11.0
    symantec norton 360 1.0
    symantec norton internet security 2005
    symantec norton internet security 2005
    symantec norton internet security 2005 11.0
    symantec norton internet security 2005 11.0.9
    symantec norton internet security 2005 11.5.6.14
    symantec norton internet security 2005_contains_nav_11.0.0
    symantec norton internet security 2006
    symantec norton internet security 2006
    symantec norton internet security 2007
    symantec norton internet security 2008
    symantec norton internet security 2005
    symantec norton internet security 2006
    symantec norton 360 1.0
    symantec norton internet security 2007
    symantec norton internet security 2008
    symantec norton internet security 2005
    symantec norton internet security 2006
    symantec antivirus 10.1
    symantec endpoint protection 11.0.6200.754