CVE-2009-2733
Achievo 1.x - Multiple Cross-Site Scripting / HTML Injection Vulnerabilities
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
4Exploited in Wild
-Decision
Descriptions
Multiple cross-site scripting (XSS) vulnerabilities in Achievo before 1.4.0 allow remote attackers to inject arbitrary web script or HTML via (1) the scheduler title in the scheduler module, and the (2) atksearch[contractnumber], (3) atksearch_AE_customer[customer], (4) atksearchmode[contracttype], and possibly (5) atksearch[contractname] parameters to the Organization Contracts administration page, reachable through dispatch.php.
Múltiples vulnerabilidades de ejecución de secuencias de comandos en sitios cruzados (XSS) en Achievo anterior a v1.4.0 permite a atacantes remotos inyectar secuencias de comandos web o HTML a través de (1) el título programador en el módulo planificador, y los parámetros (2) atksearch[contractnumber], (3) atksearch_AE_customer[customer], (4) atksearchmode[contracttype], y posiblemente (5) atksearch[contractname] en la pagina de administración Organization Contracts, accesible a través de dispatch.php.
Achievo versions 1.3.4 and below suffer from cross site scripting vulnerabilities.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2009-08-10 CVE Reserved
- 2009-10-13 First Exploit
- 2009-10-14 CVE Published
- 2024-01-19 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (11)
URL | Tag | Source |
---|---|---|
http://securitytracker.com/id?1023017 | Vdb Entry | |
http://www.bonsai-sec.com/blog/index.php/cross-site-scripting-payloads | X_refsource_misc | |
http://www.securityfocus.com/archive/1/507133/100/0/threaded | Mailing List | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/53744 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/53745 | Vdb Entry |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/33281 | 2009-10-13 | |
https://www.exploit-db.com/exploits/9863 | 2009-10-14 | |
http://www.bonsai-sec.com/research/vulnerabilities/achievo-multiple-xss-0101.txt | 2024-08-07 | |
http://www.securityfocus.com/bid/36661 | 2024-08-07 |
URL | Date | SRC |
---|---|---|
http://www.achievo.org/download/releasenotes/1_4_0 | 2018-10-10 |
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/37035 | 2018-10-10 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Achievo Search vendor "Achievo" | Achievo Search vendor "Achievo" for product "Achievo" | <= 1.3.4 Search vendor "Achievo" for product "Achievo" and version " <= 1.3.4" | - |
Affected
| ||||||
Achievo Search vendor "Achievo" | Achievo Search vendor "Achievo" for product "Achievo" | 0.7.0 Search vendor "Achievo" for product "Achievo" and version "0.7.0" | - |
Affected
| ||||||
Achievo Search vendor "Achievo" | Achievo Search vendor "Achievo" for product "Achievo" | 0.7.1 Search vendor "Achievo" for product "Achievo" and version "0.7.1" | - |
Affected
| ||||||
Achievo Search vendor "Achievo" | Achievo Search vendor "Achievo" for product "Achievo" | 0.7.2 Search vendor "Achievo" for product "Achievo" and version "0.7.2" | - |
Affected
| ||||||
Achievo Search vendor "Achievo" | Achievo Search vendor "Achievo" for product "Achievo" | 0.7.3 Search vendor "Achievo" for product "Achievo" and version "0.7.3" | - |
Affected
| ||||||
Achievo Search vendor "Achievo" | Achievo Search vendor "Achievo" for product "Achievo" | 0.8.0 Search vendor "Achievo" for product "Achievo" and version "0.8.0" | - |
Affected
| ||||||
Achievo Search vendor "Achievo" | Achievo Search vendor "Achievo" for product "Achievo" | 0.8.0_rc1 Search vendor "Achievo" for product "Achievo" and version "0.8.0_rc1" | - |
Affected
| ||||||
Achievo Search vendor "Achievo" | Achievo Search vendor "Achievo" for product "Achievo" | 0.8.0_rc2 Search vendor "Achievo" for product "Achievo" and version "0.8.0_rc2" | - |
Affected
| ||||||
Achievo Search vendor "Achievo" | Achievo Search vendor "Achievo" for product "Achievo" | 0.8.1 Search vendor "Achievo" for product "Achievo" and version "0.8.1" | - |
Affected
| ||||||
Achievo Search vendor "Achievo" | Achievo Search vendor "Achievo" for product "Achievo" | 0.9.0 Search vendor "Achievo" for product "Achievo" and version "0.9.0" | - |
Affected
| ||||||
Achievo Search vendor "Achievo" | Achievo Search vendor "Achievo" for product "Achievo" | 0.9.1 Search vendor "Achievo" for product "Achievo" and version "0.9.1" | - |
Affected
| ||||||
Achievo Search vendor "Achievo" | Achievo Search vendor "Achievo" for product "Achievo" | 1.0.0 Search vendor "Achievo" for product "Achievo" and version "1.0.0" | - |
Affected
| ||||||
Achievo Search vendor "Achievo" | Achievo Search vendor "Achievo" for product "Achievo" | 1.0.0 Search vendor "Achievo" for product "Achievo" and version "1.0.0" | rc1 |
Affected
| ||||||
Achievo Search vendor "Achievo" | Achievo Search vendor "Achievo" for product "Achievo" | 1.0.0 Search vendor "Achievo" for product "Achievo" and version "1.0.0" | rc2 |
Affected
| ||||||
Achievo Search vendor "Achievo" | Achievo Search vendor "Achievo" for product "Achievo" | 1.0.0 Search vendor "Achievo" for product "Achievo" and version "1.0.0" | rc3 |
Affected
| ||||||
Achievo Search vendor "Achievo" | Achievo Search vendor "Achievo" for product "Achievo" | 1.0.1 Search vendor "Achievo" for product "Achievo" and version "1.0.1" | - |
Affected
| ||||||
Achievo Search vendor "Achievo" | Achievo Search vendor "Achievo" for product "Achievo" | 1.0.2 Search vendor "Achievo" for product "Achievo" and version "1.0.2" | - |
Affected
| ||||||
Achievo Search vendor "Achievo" | Achievo Search vendor "Achievo" for product "Achievo" | 1.0.3 Search vendor "Achievo" for product "Achievo" and version "1.0.3" | - |
Affected
| ||||||
Achievo Search vendor "Achievo" | Achievo Search vendor "Achievo" for product "Achievo" | 1.0.4 Search vendor "Achievo" for product "Achievo" and version "1.0.4" | - |
Affected
| ||||||
Achievo Search vendor "Achievo" | Achievo Search vendor "Achievo" for product "Achievo" | 1.1.0 Search vendor "Achievo" for product "Achievo" and version "1.1.0" | - |
Affected
| ||||||
Achievo Search vendor "Achievo" | Achievo Search vendor "Achievo" for product "Achievo" | 1.1.0 Search vendor "Achievo" for product "Achievo" and version "1.1.0" | rc1 |
Affected
| ||||||
Achievo Search vendor "Achievo" | Achievo Search vendor "Achievo" for product "Achievo" | 1.1.0 Search vendor "Achievo" for product "Achievo" and version "1.1.0" | rc2 |
Affected
| ||||||
Achievo Search vendor "Achievo" | Achievo Search vendor "Achievo" for product "Achievo" | 1.1.0 Search vendor "Achievo" for product "Achievo" and version "1.1.0" | rc3 |
Affected
| ||||||
Achievo Search vendor "Achievo" | Achievo Search vendor "Achievo" for product "Achievo" | 1.2.0 Search vendor "Achievo" for product "Achievo" and version "1.2.0" | - |
Affected
| ||||||
Achievo Search vendor "Achievo" | Achievo Search vendor "Achievo" for product "Achievo" | 1.2.0 Search vendor "Achievo" for product "Achievo" and version "1.2.0" | rc1 |
Affected
| ||||||
Achievo Search vendor "Achievo" | Achievo Search vendor "Achievo" for product "Achievo" | 1.2.1 Search vendor "Achievo" for product "Achievo" and version "1.2.1" | - |
Affected
| ||||||
Achievo Search vendor "Achievo" | Achievo Search vendor "Achievo" for product "Achievo" | 1.3.0 Search vendor "Achievo" for product "Achievo" and version "1.3.0" | - |
Affected
| ||||||
Achievo Search vendor "Achievo" | Achievo Search vendor "Achievo" for product "Achievo" | 1.3.0 Search vendor "Achievo" for product "Achievo" and version "1.3.0" | rc1 |
Affected
| ||||||
Achievo Search vendor "Achievo" | Achievo Search vendor "Achievo" for product "Achievo" | 1.3.0 Search vendor "Achievo" for product "Achievo" and version "1.3.0" | rc2 |
Affected
| ||||||
Achievo Search vendor "Achievo" | Achievo Search vendor "Achievo" for product "Achievo" | 1.3.1 Search vendor "Achievo" for product "Achievo" and version "1.3.1" | - |
Affected
| ||||||
Achievo Search vendor "Achievo" | Achievo Search vendor "Achievo" for product "Achievo" | 1.3.2 Search vendor "Achievo" for product "Achievo" and version "1.3.2" | - |
Affected
| ||||||
Achievo Search vendor "Achievo" | Achievo Search vendor "Achievo" for product "Achievo" | 1.3.3 Search vendor "Achievo" for product "Achievo" and version "1.3.3" | - |
Affected
|