4.3
CVSSv2

CVE-2009-1288

Published: 13/04/2009 Updated: 10/10/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 440
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in the Advanced Management Module (AMM) on the IBM BladeCenter, including the BladeCenter H with BPET36H 54, allow remote malicious users to inject arbitrary web script or HTML via (1) the username in a login action or (2) the PATH parameter to private/file_management.ssi in the File manager.

Vulnerable Product Search on Vulmon Subscribe to Product

ibm advanced management module 1.36h

ibm bladecenter e

ibm bladecenter h

ibm bladecenter hc10

ibm bladecenter hs12

ibm bladecenter hs20

ibm bladecenter hs21

ibm bladecenter hs21 xm

ibm bladecenter ht

ibm bladecenter js12

ibm bladecenter js21

ibm bladecenter js22

ibm bladecenter ls20

ibm bladecenter ls21

ibm bladecenter ls41

ibm bladecenter qs21

ibm bladecenter qs22

ibm bladecenter s

ibm bladecenter t

Exploits

source: wwwsecurityfocuscom/bid/34447/info IBM BladeCenter Advanced Management Module is prone to the following remote vulnerabilities: - An HTML-injection vulnerability - A cross-site scripting vulnerability - An information-disclosure vulnerability - Multiple cross-site request-forgery vulnerabilities An attacker can exploit these ...
source: wwwsecurityfocuscom/bid/34447/info IBM BladeCenter Advanced Management Module is prone to the following remote vulnerabilities: - An HTML-injection vulnerability - A cross-site scripting vulnerability - An information-disclosure vulnerability - Multiple cross-site request-forgery vulnerabilities An attacker can exploit these iss ...