4.3
CVSSv2

CVE-2009-2907

Published: 24/03/2010 Updated: 25/03/2010
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in SpringSource tc Server 6.0.20.B and previous versions, Application Management Suite (AMS) prior to 2.0.0.SR4, Hyperic HQ Open Source prior to 4.2.x, Hyperic HQ 4.0 Enterprise prior to 4.0.3.2, and Hyperic HQ 4.1 Enterprise prior to 4.1.2.1 allow remote malicious users to inject arbitrary web script or HTML via the description field and unspecified "input fields."

Vulnerable Product Search on Vulmon Subscribe to Product

springsource tc server

springsource hyperic hq

springsource application management suite

Exploits

source: wwwsecurityfocuscom/bid/38913/info Multiple SpringSource Products are prone to multiple HTML-injection vulnerabilities because they fail to sufficiently sanitize user-supplied data Attacker-supplied HTML or JavaScript code could run in the context of the affected site, potentially allowing the attacker to steal cookie-based auth ...
SpringSource Hyperic HQ suffers from multiple stored cross site scripting vulnerability ...