// For flags

CVE-2009-2733

Achievo 1.x - Multiple Cross-Site Scripting / HTML Injection Vulnerabilities

Severity Score

4.3
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

4
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Multiple cross-site scripting (XSS) vulnerabilities in Achievo before 1.4.0 allow remote attackers to inject arbitrary web script or HTML via (1) the scheduler title in the scheduler module, and the (2) atksearch[contractnumber], (3) atksearch_AE_customer[customer], (4) atksearchmode[contracttype], and possibly (5) atksearch[contractname] parameters to the Organization Contracts administration page, reachable through dispatch.php.

Múltiples vulnerabilidades de ejecución de secuencias de comandos en sitios cruzados (XSS) en Achievo anterior a v1.4.0 permite a atacantes remotos inyectar secuencias de comandos web o HTML a través de (1) el título programador en el módulo planificador, y los parámetros (2) atksearch[contractnumber], (3) atksearch_AE_customer[customer], (4) atksearchmode[contracttype], y posiblemente (5) atksearch[contractname] en la pagina de administración Organization Contracts, accesible a través de dispatch.php.

Achievo versions 1.3.4 and below suffer from cross site scripting vulnerabilities.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
None
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2009-08-10 CVE Reserved
  • 2009-10-13 First Exploit
  • 2009-10-14 CVE Published
  • 2024-01-19 EPSS Updated
  • 2024-08-07 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Achievo
Search vendor "Achievo"
Achievo
Search vendor "Achievo" for product "Achievo"
<= 1.3.4
Search vendor "Achievo" for product "Achievo" and version " <= 1.3.4"
-
Affected
Achievo
Search vendor "Achievo"
Achievo
Search vendor "Achievo" for product "Achievo"
0.7.0
Search vendor "Achievo" for product "Achievo" and version "0.7.0"
-
Affected
Achievo
Search vendor "Achievo"
Achievo
Search vendor "Achievo" for product "Achievo"
0.7.1
Search vendor "Achievo" for product "Achievo" and version "0.7.1"
-
Affected
Achievo
Search vendor "Achievo"
Achievo
Search vendor "Achievo" for product "Achievo"
0.7.2
Search vendor "Achievo" for product "Achievo" and version "0.7.2"
-
Affected
Achievo
Search vendor "Achievo"
Achievo
Search vendor "Achievo" for product "Achievo"
0.7.3
Search vendor "Achievo" for product "Achievo" and version "0.7.3"
-
Affected
Achievo
Search vendor "Achievo"
Achievo
Search vendor "Achievo" for product "Achievo"
0.8.0
Search vendor "Achievo" for product "Achievo" and version "0.8.0"
-
Affected
Achievo
Search vendor "Achievo"
Achievo
Search vendor "Achievo" for product "Achievo"
0.8.0_rc1
Search vendor "Achievo" for product "Achievo" and version "0.8.0_rc1"
-
Affected
Achievo
Search vendor "Achievo"
Achievo
Search vendor "Achievo" for product "Achievo"
0.8.0_rc2
Search vendor "Achievo" for product "Achievo" and version "0.8.0_rc2"
-
Affected
Achievo
Search vendor "Achievo"
Achievo
Search vendor "Achievo" for product "Achievo"
0.8.1
Search vendor "Achievo" for product "Achievo" and version "0.8.1"
-
Affected
Achievo
Search vendor "Achievo"
Achievo
Search vendor "Achievo" for product "Achievo"
0.9.0
Search vendor "Achievo" for product "Achievo" and version "0.9.0"
-
Affected
Achievo
Search vendor "Achievo"
Achievo
Search vendor "Achievo" for product "Achievo"
0.9.1
Search vendor "Achievo" for product "Achievo" and version "0.9.1"
-
Affected
Achievo
Search vendor "Achievo"
Achievo
Search vendor "Achievo" for product "Achievo"
1.0.0
Search vendor "Achievo" for product "Achievo" and version "1.0.0"
-
Affected
Achievo
Search vendor "Achievo"
Achievo
Search vendor "Achievo" for product "Achievo"
1.0.0
Search vendor "Achievo" for product "Achievo" and version "1.0.0"
rc1
Affected
Achievo
Search vendor "Achievo"
Achievo
Search vendor "Achievo" for product "Achievo"
1.0.0
Search vendor "Achievo" for product "Achievo" and version "1.0.0"
rc2
Affected
Achievo
Search vendor "Achievo"
Achievo
Search vendor "Achievo" for product "Achievo"
1.0.0
Search vendor "Achievo" for product "Achievo" and version "1.0.0"
rc3
Affected
Achievo
Search vendor "Achievo"
Achievo
Search vendor "Achievo" for product "Achievo"
1.0.1
Search vendor "Achievo" for product "Achievo" and version "1.0.1"
-
Affected
Achievo
Search vendor "Achievo"
Achievo
Search vendor "Achievo" for product "Achievo"
1.0.2
Search vendor "Achievo" for product "Achievo" and version "1.0.2"
-
Affected
Achievo
Search vendor "Achievo"
Achievo
Search vendor "Achievo" for product "Achievo"
1.0.3
Search vendor "Achievo" for product "Achievo" and version "1.0.3"
-
Affected
Achievo
Search vendor "Achievo"
Achievo
Search vendor "Achievo" for product "Achievo"
1.0.4
Search vendor "Achievo" for product "Achievo" and version "1.0.4"
-
Affected
Achievo
Search vendor "Achievo"
Achievo
Search vendor "Achievo" for product "Achievo"
1.1.0
Search vendor "Achievo" for product "Achievo" and version "1.1.0"
-
Affected
Achievo
Search vendor "Achievo"
Achievo
Search vendor "Achievo" for product "Achievo"
1.1.0
Search vendor "Achievo" for product "Achievo" and version "1.1.0"
rc1
Affected
Achievo
Search vendor "Achievo"
Achievo
Search vendor "Achievo" for product "Achievo"
1.1.0
Search vendor "Achievo" for product "Achievo" and version "1.1.0"
rc2
Affected
Achievo
Search vendor "Achievo"
Achievo
Search vendor "Achievo" for product "Achievo"
1.1.0
Search vendor "Achievo" for product "Achievo" and version "1.1.0"
rc3
Affected
Achievo
Search vendor "Achievo"
Achievo
Search vendor "Achievo" for product "Achievo"
1.2.0
Search vendor "Achievo" for product "Achievo" and version "1.2.0"
-
Affected
Achievo
Search vendor "Achievo"
Achievo
Search vendor "Achievo" for product "Achievo"
1.2.0
Search vendor "Achievo" for product "Achievo" and version "1.2.0"
rc1
Affected
Achievo
Search vendor "Achievo"
Achievo
Search vendor "Achievo" for product "Achievo"
1.2.1
Search vendor "Achievo" for product "Achievo" and version "1.2.1"
-
Affected
Achievo
Search vendor "Achievo"
Achievo
Search vendor "Achievo" for product "Achievo"
1.3.0
Search vendor "Achievo" for product "Achievo" and version "1.3.0"
-
Affected
Achievo
Search vendor "Achievo"
Achievo
Search vendor "Achievo" for product "Achievo"
1.3.0
Search vendor "Achievo" for product "Achievo" and version "1.3.0"
rc1
Affected
Achievo
Search vendor "Achievo"
Achievo
Search vendor "Achievo" for product "Achievo"
1.3.0
Search vendor "Achievo" for product "Achievo" and version "1.3.0"
rc2
Affected
Achievo
Search vendor "Achievo"
Achievo
Search vendor "Achievo" for product "Achievo"
1.3.1
Search vendor "Achievo" for product "Achievo" and version "1.3.1"
-
Affected
Achievo
Search vendor "Achievo"
Achievo
Search vendor "Achievo" for product "Achievo"
1.3.2
Search vendor "Achievo" for product "Achievo" and version "1.3.2"
-
Affected
Achievo
Search vendor "Achievo"
Achievo
Search vendor "Achievo" for product "Achievo"
1.3.3
Search vendor "Achievo" for product "Achievo" and version "1.3.3"
-
Affected