Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2009-1294Cross-site Scripting in Enterprise Portal

Severity
4.3MEDIUMNVD
EPSS
2.6%
top 14.46%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedApr 16
Latest updateMay 2

Description

Multiple cross-site scripting (XSS) vulnerabilities in web/guest/home in the Liferay 4.3.0 portal in Novell Teaming 1.0 through SP3 (1.0.3) allow remote attackers to inject arbitrary web script or HTML via the (1) p_p_state or (2) p_p_mode parameters.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages2 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-94fp-6r45-7325: Multiple cross-site scripting (XSS) vulnerabilities in web/guest/home in the Liferay 42022-05-02
CVEList
CVE-2009-1294: Multiple cross-site scripting (XSS) vulnerabilities in web/guest/home in the Liferay 42009-04-16

💥Exploits & PoCs

2
Exploit-DB
Novell Groupwise Client 7.0.3.1294 - ActiveX Denial of Service (PoC)2009-09-15
Exploit-DB
Novell Teaming 1.0 - User Enumeration / Multiple Cross-Site Scripting Vulnerabilities2009-04-15
CVE-2009-1294 — Cross-site Scripting | cvebase