Lucene search

K
cve[email protected]CVE-2009-0611
HistoryFeb 17, 2009 - 5:30 p.m.

CVE-2009-0611

2009-02-1717:30:06
CWE-79
web.nvd.nist.gov
19
cve-2009-0611
cross-site scripting
xss
quickfinder server
novell open enterprise server
nvd
vulnerability

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

5.8 Medium

AI Score

Confidence

High

0.849 High

EPSS

Percentile

98.5%

Multiple cross-site scripting (XSS) vulnerabilities in qfsearch/AdminServlet in QuickFinder Server in Novell Open Enterprise Server 1.x allow remote attackers to inject arbitrary web script or HTML via (1) the siteloc parameter in a displayaddsite action, the site parameter in a (2) generalproperties or (3) clusterserviceproperties action, (4) the adminurl parameter in a global action, or (5) the print-list parameter.

Affected configurations

NVD
Node
novellopen_enterprise_serverMatch1.x

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

5.8 Medium

AI Score

Confidence

High

0.849 High

EPSS

Percentile

98.5%