Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2009-2897

Опубликовано: 13 окт. 2009
Источник: nvd
CVSS2: 4.3
EPSS Низкий

Описание

Multiple cross-site scripting (XSS) vulnerabilities in hq/web/common/GenericError.jsp in the generic exception handler in the web interface in SpringSource Hyperic HQ 3.2.x before 3.2.6.1, 4.0.x before 4.0.3.1, 4.1.x before 4.1.2.1, and 4.2-beta1; Application Management Suite (AMS) 2.0.0.SR3; and tc Server 6.0.20.B allow remote attackers to inject arbitrary web script or HTML via invalid values for numerical parameters, as demonstrated by an uncaught java.lang.NumberFormatException exception resulting from (1) the typeId parameter to mastheadAttach.do, (2) the eid parameter to Resource.do, and (3) the u parameter in a view action to admin/user/UserAdmin.do. NOTE: some of these details are obtained from third party information.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:springsource:application_management_suite:2.0.0:sr3:*:*:*:*:*:*
cpe:2.3:a:springsource:hyperic_hq:3.2:beta_1:*:*:*:*:*:*
cpe:2.3:a:springsource:hyperic_hq:3.2.0:*:*:*:*:*:*:*
cpe:2.3:a:springsource:hyperic_hq:3.2.1:*:*:*:*:*:*:*
cpe:2.3:a:springsource:hyperic_hq:3.2.2:*:*:*:*:*:*:*
cpe:2.3:a:springsource:hyperic_hq:3.2.3:*:*:*:*:*:*:*
cpe:2.3:a:springsource:hyperic_hq:3.2.4:*:*:*:*:*:*:*
cpe:2.3:a:springsource:hyperic_hq:3.2.5:*:*:*:*:*:*:*
cpe:2.3:a:springsource:hyperic_hq:3.2.6:*:*:*:*:*:*:*
cpe:2.3:a:springsource:hyperic_hq:4.0.0:*:*:*:*:*:*:*
cpe:2.3:a:springsource:hyperic_hq:4.0.1:*:*:*:*:*:*:*
cpe:2.3:a:springsource:hyperic_hq:4.0.2:*:*:*:*:*:*:*
cpe:2.3:a:springsource:hyperic_hq:4.0.3:*:*:*:*:*:*:*
cpe:2.3:a:springsource:hyperic_hq:4.1.0:*:*:*:*:*:*:*
cpe:2.3:a:springsource:hyperic_hq:4.1.1:*:*:*:*:*:*:*
cpe:2.3:a:springsource:hyperic_hq:4.1.2:*:*:*:*:*:*:*
cpe:2.3:a:springsource:hyperic_hq:4.2:beta_1:*:*:*:*:*:*
cpe:2.3:a:springsource:tc_server:6.0.20:b:*:*:*:*:*:*

EPSS

Процентиль: 71%
0.00666
Низкий

4.3 Medium

CVSS2

Дефекты

CWE-79

Связанные уязвимости

github
почти 4 года назад

Multiple cross-site scripting (XSS) vulnerabilities in hq/web/common/GenericError.jsp in the generic exception handler in the web interface in SpringSource Hyperic HQ 3.2.x before 3.2.6.1, 4.0.x before 4.0.3.1, 4.1.x before 4.1.2.1, and 4.2-beta1; Application Management Suite (AMS) 2.0.0.SR3; and tc Server 6.0.20.B allow remote attackers to inject arbitrary web script or HTML via invalid values for numerical parameters, as demonstrated by an uncaught java.lang.NumberFormatException exception resulting from (1) the typeId parameter to mastheadAttach.do, (2) the eid parameter to Resource.do, and (3) the u parameter in a view action to admin/user/UserAdmin.do. NOTE: some of these details are obtained from third party information.

EPSS

Процентиль: 71%
0.00666
Низкий

4.3 Medium

CVSS2

Дефекты

CWE-79