4.3
CVSSv2

CVE-2009-1798

Published: 28/12/2009 Updated: 29/06/2010
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities on the Network Management Card (NMC) on American Power Conversion (APC) Switched Rack PDU (aka Rack Mount Power Distribution) devices and other devices allow remote malicious users to inject arbitrary web script or HTML via unspecified vectors. NOTE: the login_username vector for Forms/login1 is already covered by CVE-2009-4406.

Vulnerable Product Search on Vulmon Subscribe to Product

apc network_management_card

apc switched_rack_pdu

Exploits

source: wwwsecurityfocuscom/bid/37338/info The APC Network Management Card is prone to multiple cross-site request-forgery and cross-site scripting vulnerabilities An attacker can exploit the cross-site request forgery issues to alter the settings on affected devices, which may lead to further network-based attacks The attacker can e ...