Vulnerability Name: | CVE-2009-3030 (CCN-53669) | ||||||||
Assigned: | 2009-10-06 | ||||||||
Published: | 2009-10-06 | ||||||||
Updated: | 2017-08-17 | ||||||||
Summary: | Cross-site scripting (XSS) vulnerability in Symantec SecurityExpressions Audit and Compliance Server 4.1.1, 4.1, and earlier allows remote attackers to inject arbitrary web script or HTML via vectors that trigger an error message in a response, related to an "HTML Injection issue." | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N) 3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-79 | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2009-3030 Source: CCN Type: SA36972 Symantec SecurityExpressions Cross-Site Scripting and Script Insertion Source: SECUNIA Type: Vendor Advisory 36972 Source: CCN Type: SECTRACK ID: 1022989 Symantec SecurityExpressions Audit and Compliance Server Input Validation Hole Permits Cross-Site Scripting Attacks Source: SECTRACK Type: UNKNOWN 1022989 Source: OSVDB Type: UNKNOWN 58650 Source: CCN Type: OSVDB ID: 58650 Symantec SecurityExpressions Audit and Compliance Server Unspecified HTML Injection Source: BID Type: Patch 36571 Source: CCN Type: BID-36571 Symantec SecurityExpressions Audit and Compliance Server Error Message HTML Injection Vulnerability Source: CCN Type: SYM09-014 Symantec Security Expressions Cross-site Scripting and HTML Injection Vulnerability Source: CONFIRM Type: UNKNOWN http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2009&suid=20091006_00 Source: VUPEN Type: Vendor Advisory ADV-2009-2849 Source: XF Type: UNKNOWN securityexpressions-error-response-xss(53669) Source: XF Type: UNKNOWN securityexpressions-error-response-xss(53669) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |