4.3
CVSSv2

CVE-2009-2733

Published: 16/10/2009 Updated: 10/10/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 440
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in Achievo prior to 1.4.0 allow remote malicious users to inject arbitrary web script or HTML via (1) the scheduler title in the scheduler module, and the (2) atksearch[contractnumber], (3) atksearch_AE_customer[customer], (4) atksearchmode[contracttype], and possibly (5) atksearch[contractname] parameters to the Organization Contracts administration page, reachable through dispatch.php.

Vulnerable Product Search on Vulmon Subscribe to Product

achievo achievo 0.8.0_rc1

achievo achievo 0.8.0

achievo achievo 0.7.3

achievo achievo 1.3.3

achievo achievo

achievo achievo 1.1.0

achievo achievo 1.0.0

achievo achievo 0.9.0

achievo achievo 0.7.2

achievo achievo 0.9.1

achievo achievo 1.3.0

achievo achievo 1.0.4

achievo achievo 1.0.3

achievo achievo 0.7.1

achievo achievo 0.7.0

achievo achievo 1.3.2

achievo achievo 1.3.1

achievo achievo 0.8.1

achievo achievo 0.8.0_rc2

achievo achievo 1.2.0

achievo achievo 1.2.1

achievo achievo 1.0.2

achievo achievo 1.0.1

Exploits

source: wwwsecurityfocuscom/bid/36661/info Achievo is prone to multiple cross-site scripting and HTML-injection vulnerabilities because it fails to sufficiently sanitize user-supplied data Attacker-supplied HTML or JavaScript code could run in the context of the affected site, potentially allowing the attacker to steal cookie-based auth ...
Bonsai Information Security - Advisory wwwbonsai-seccom/research/ Multiple XSS in Achievo 1 *Advisory Information* Title: Multiple XSS in Achievo Advisory ID: BONSAI-2009-0101 Advisory URL: wwwbonsai-seccom/research/vulnerabilities/achievo-multiple-xss-0101txt Date published: 2009-10 ...