CVE-2009-3300
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Multiple cross-site scripting (XSS) vulnerabilities in the Identity Provider (IdP) 1.3.x before 1.3.4 and 2.x before 2.1.5, and the Service Provider 1.3.x before 1.3.5 and 2.x before 2.3, in Internet2 Middleware Initiative Shibboleth allow remote attackers to inject arbitrary web script or HTML via URLs that are encountered in redirections, and appear in automatically generated forms.
Múltiples vulnerabilidades de secuencias de comandos en sitios cruzados (XSS) en Identity Provider (IdP) v1.3.x anteriores a v1.3.4 y v2.x anteriores a v2.1.5, y el Service Provider v1.3.x anteriores a v1.3.5 y v2.x anteriores a v2.3, en Internet2 Middleware Initiative Shibboleth permite a atacantes remotos inyectar secuencias de comandos web o HTML de su elección mediante URLs que se encuentran en redirecciones, y aparecen en formularios generados automáticamente.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2009-09-22 CVE Reserved
- 2009-11-06 CVE Published
- 2023-03-07 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/54140 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/37237 | 2017-08-17 | |
http://shibboleth.internet2.edu/secadv/secadv_20091104.txt | 2017-08-17 | |
http://www.debian.org/security/2009/dsa-1947 | 2017-08-17 | |
http://www.vupen.com/english/advisories/2009/3150 | 2017-08-17 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Internet2 Search vendor "Internet2" | Identity Provider Search vendor "Internet2" for product "Identity Provider" | 1.3 Search vendor "Internet2" for product "Identity Provider" and version "1.3" | - |
Affected
| ||||||
Internet2 Search vendor "Internet2" | Identity Provider Search vendor "Internet2" for product "Identity Provider" | 1.3.1 Search vendor "Internet2" for product "Identity Provider" and version "1.3.1" | - |
Affected
| ||||||
Internet2 Search vendor "Internet2" | Identity Provider Search vendor "Internet2" for product "Identity Provider" | 1.3.2 Search vendor "Internet2" for product "Identity Provider" and version "1.3.2" | - |
Affected
| ||||||
Internet2 Search vendor "Internet2" | Identity Provider Search vendor "Internet2" for product "Identity Provider" | 1.3.3 Search vendor "Internet2" for product "Identity Provider" and version "1.3.3" | - |
Affected
| ||||||
Internet2 Search vendor "Internet2" | Identity Provider Search vendor "Internet2" for product "Identity Provider" | 2.1.0 Search vendor "Internet2" for product "Identity Provider" and version "2.1.0" | - |
Affected
| ||||||
Internet2 Search vendor "Internet2" | Identity Provider Search vendor "Internet2" for product "Identity Provider" | 2.1.1 Search vendor "Internet2" for product "Identity Provider" and version "2.1.1" | - |
Affected
| ||||||
Internet2 Search vendor "Internet2" | Identity Provider Search vendor "Internet2" for product "Identity Provider" | 2.1.2 Search vendor "Internet2" for product "Identity Provider" and version "2.1.2" | - |
Affected
| ||||||
Internet2 Search vendor "Internet2" | Identity Provider Search vendor "Internet2" for product "Identity Provider" | 2.1.3 Search vendor "Internet2" for product "Identity Provider" and version "2.1.3" | - |
Affected
| ||||||
Internet2 Search vendor "Internet2" | Identity Provider Search vendor "Internet2" for product "Identity Provider" | 2.1.4 Search vendor "Internet2" for product "Identity Provider" and version "2.1.4" | - |
Affected
| ||||||
Internet2 Search vendor "Internet2" | Service Provider Search vendor "Internet2" for product "Service Provider" | 1.3 Search vendor "Internet2" for product "Service Provider" and version "1.3" | - |
Affected
| ||||||
Internet2 Search vendor "Internet2" | Service Provider Search vendor "Internet2" for product "Service Provider" | 1.3.1 Search vendor "Internet2" for product "Service Provider" and version "1.3.1" | - |
Affected
| ||||||
Internet2 Search vendor "Internet2" | Service Provider Search vendor "Internet2" for product "Service Provider" | 1.3.2 Search vendor "Internet2" for product "Service Provider" and version "1.3.2" | - |
Affected
| ||||||
Internet2 Search vendor "Internet2" | Service Provider Search vendor "Internet2" for product "Service Provider" | 1.3.3 Search vendor "Internet2" for product "Service Provider" and version "1.3.3" | - |
Affected
| ||||||
Internet2 Search vendor "Internet2" | Service Provider Search vendor "Internet2" for product "Service Provider" | 2.0 Search vendor "Internet2" for product "Service Provider" and version "2.0" | - |
Affected
| ||||||
Internet2 Search vendor "Internet2" | Service Provider Search vendor "Internet2" for product "Service Provider" | 2.1 Search vendor "Internet2" for product "Service Provider" and version "2.1" | - |
Affected
| ||||||
Internet2 Search vendor "Internet2" | Service Provider Search vendor "Internet2" for product "Service Provider" | 2.2 Search vendor "Internet2" for product "Service Provider" and version "2.2" | - |
Affected
|