CVE-2009-3036

medium

Description

Cross-site scripting (XSS) vulnerability in the console in Symantec IM Manager 8.3 and 8.4 before 8.4.13 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

References

http://osvdb.org/62446

http://secunia.com/advisories/38672

http://www.securityfocus.com/bid/38241

http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2010&suid=20100218_00

http://www.vupen.com/english/advisories/2010/0438

Details

Source: MITRE

Published: 2010-02-23

Updated: 2013-02-07

Type: CWE-79

Risk Information

CVSS v2

Base Score: 4.3

Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Impact Score: 2.9

Exploitability Score: 8.6

Severity: MEDIUM