Multiple cross-site scripting (XSS) vulnerabilities on the Network Management Card (NMC) on American Power Conversion (APC) Switched Rack PDU (aka Rack Mount Power Distribution) devices and other devices allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: the login_username vector for Forms/login1 is already covered by CVE-2009-4406.
References
Link | Resource |
---|---|
http://holisticinfosec.org/content/view/111/45/ | |
http://nam-en.apc.com/cgi-bin/nam_en.cfg/php/enduser/std_adp.php?p_faqid=10887 | Vendor Advisory |
http://secunia.com/advisories/37744 | Vendor Advisory |
http://www.kb.cert.org/vuls/id/166739 | US Government Resource |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2022-10-03T16:23:59
Updated: 2022-10-03T16:23:59
Reserved: 2022-10-03T00:00:00
Link: CVE-2009-1798
JSON object: View
NVD Information
Status : Analyzed
Published: 2009-12-28T19:30:00.267
Modified: 2010-06-29T04:00:00.000
Link: CVE-2009-1798
JSON object: View
Redhat Information
No data.
CWE