Vulnerability Name: | CVE-2009-3029 (CCN-53668) | ||||||||
Assigned: | 2009-10-06 | ||||||||
Published: | 2009-10-06 | ||||||||
Updated: | 2013-02-07 | ||||||||
Summary: | Cross-site scripting (XSS) vulnerability in the console in Symantec SecurityExpressions Audit and Compliance Server 4.1.1, 4.1, and earlier allows remote authenticated users to inject arbitrary web script or HTML via "external client input" that triggers crafted error messages. | ||||||||
CVSS v3 Severity: | 2.6 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 3.5 Low (CVSS v2 Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N) 3.0 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N/E:H/RL:OF/RC:C)
3.0 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N/E:H/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-79 | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2009-3029 Source: CCN Type: SA36972 Symantec SecurityExpressions Cross-Site Scripting and Script Insertion Source: SECUNIA Type: Vendor Advisory 36972 Source: CCN Type: SECTRACK ID: 1022989 Symantec SecurityExpressions Audit and Compliance Server Input Validation Hole Permits Cross-Site Scripting Attacks Source: SECTRACK Type: UNKNOWN 1022989 Source: OSVDB Type: UNKNOWN 58651 Source: CCN Type: OSVDB ID: 58651 Symantec SecurityExpressions Audit and Compliance Server Unspecified XSS Source: BID Type: Patch 36570 Source: CCN Type: BID-36570 Symantec SecurityExpressions Audit and Compliance Server Cross Site Scripting Vulnerability Source: CCN Type: SYM09-014 Symantec Security Expressions Cross-site Scripting and HTML Injection Vulnerability Source: CONFIRM Type: UNKNOWN http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2009&suid=20091006_00 Source: VUPEN Type: Vendor Advisory ADV-2009-2849 Source: XF Type: UNKNOWN securityexpressions-console-xss(53668) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |