4.3
CVSSv2

CVE-2009-1294

Published: 16/04/2009 Updated: 10/10/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in web/guest/home in the Liferay 4.3.0 portal in Novell Teaming 1.0 through SP3 (1.0.3) allow remote malicious users to inject arbitrary web script or HTML via the (1) p_p_state or (2) p_p_mode parameters.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

novell teaming 1.0

novell teaming 1.0.2

novell teaming 1.0.3

novell teaming 1.0.1

liferay liferay_enterprise_portal 4.3.0

Exploits

source: wwwsecurityfocuscom/bid/34531/info Novell Teaming is prone to a user-enumeration weakness and multiple cross-site scripting vulnerabilities A remote attacker can exploit the user-enumeration weakness to enumerate valid usernames and then perform brute-force attacks; other attacks are also possible The attacker may leverage the ...