// For flags

CVE-2009-4459

 

Severity Score

4.3
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Redmine 0.8.7 and earlier uses the title tag before defining the character encoding in a meta tag, which allows remote attackers to conduct cross-site scripting (XSS) attacks and inject arbitrary script via UTF-7 encoded values in the title parameter to a new issue page, which may be interpreted as script by Internet Explorer 7 and 8.

Redmine 0.8.7 y versiones anteriores usa la etiqueta título antes de definir el caracter de codificación en una etiqueta META lo que permite a atacantes remotos realizar ataques de secuencias de comandos en sitios cruzados (XSS) e inyectar secuencias de comandos de su elección mediante valores con codificación UTF-7 en el parámetro título para una página de nueva emisión, lo que puede ser interpratado como un script por Internet Explorer 7 y 8.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
None
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2009-12-30 CVE Reserved
  • 2009-12-30 CVE Published
  • 2023-03-07 EPSS Updated
  • 2024-08-07 CVE Updated
  • 2024-08-07 First Exploit
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Redmine
Search vendor "Redmine"
Redmine
Search vendor "Redmine" for product "Redmine"
<= 0.8.7
Search vendor "Redmine" for product "Redmine" and version " <= 0.8.7"
-
Affected
Redmine
Search vendor "Redmine"
Redmine
Search vendor "Redmine" for product "Redmine"
0.1.0
Search vendor "Redmine" for product "Redmine" and version "0.1.0"
-
Affected
Redmine
Search vendor "Redmine"
Redmine
Search vendor "Redmine" for product "Redmine"
0.2.1
Search vendor "Redmine" for product "Redmine" and version "0.2.1"
-
Affected
Redmine
Search vendor "Redmine"
Redmine
Search vendor "Redmine" for product "Redmine"
0.2.2
Search vendor "Redmine" for product "Redmine" and version "0.2.2"
-
Affected
Redmine
Search vendor "Redmine"
Redmine
Search vendor "Redmine" for product "Redmine"
0.3.0
Search vendor "Redmine" for product "Redmine" and version "0.3.0"
-
Affected
Redmine
Search vendor "Redmine"
Redmine
Search vendor "Redmine" for product "Redmine"
0.4.0
Search vendor "Redmine" for product "Redmine" and version "0.4.0"
-
Affected
Redmine
Search vendor "Redmine"
Redmine
Search vendor "Redmine" for product "Redmine"
0.4.1
Search vendor "Redmine" for product "Redmine" and version "0.4.1"
-
Affected
Redmine
Search vendor "Redmine"
Redmine
Search vendor "Redmine" for product "Redmine"
0.4.2
Search vendor "Redmine" for product "Redmine" and version "0.4.2"
-
Affected
Redmine
Search vendor "Redmine"
Redmine
Search vendor "Redmine" for product "Redmine"
0.5.0
Search vendor "Redmine" for product "Redmine" and version "0.5.0"
-
Affected
Redmine
Search vendor "Redmine"
Redmine
Search vendor "Redmine" for product "Redmine"
0.5.1
Search vendor "Redmine" for product "Redmine" and version "0.5.1"
-
Affected
Redmine
Search vendor "Redmine"
Redmine
Search vendor "Redmine" for product "Redmine"
0.6.0
Search vendor "Redmine" for product "Redmine" and version "0.6.0"
-
Affected
Redmine
Search vendor "Redmine"
Redmine
Search vendor "Redmine" for product "Redmine"
0.6.1
Search vendor "Redmine" for product "Redmine" and version "0.6.1"
-
Affected
Redmine
Search vendor "Redmine"
Redmine
Search vendor "Redmine" for product "Redmine"
0.6.2
Search vendor "Redmine" for product "Redmine" and version "0.6.2"
-
Affected
Redmine
Search vendor "Redmine"
Redmine
Search vendor "Redmine" for product "Redmine"
0.6.3
Search vendor "Redmine" for product "Redmine" and version "0.6.3"
-
Affected
Redmine
Search vendor "Redmine"
Redmine
Search vendor "Redmine" for product "Redmine"
0.6.4
Search vendor "Redmine" for product "Redmine" and version "0.6.4"
-
Affected
Redmine
Search vendor "Redmine"
Redmine
Search vendor "Redmine" for product "Redmine"
0.7.0
Search vendor "Redmine" for product "Redmine" and version "0.7.0"
-
Affected
Redmine
Search vendor "Redmine"
Redmine
Search vendor "Redmine" for product "Redmine"
0.7.0
Search vendor "Redmine" for product "Redmine" and version "0.7.0"
rc1
Affected
Redmine
Search vendor "Redmine"
Redmine
Search vendor "Redmine" for product "Redmine"
0.7.1
Search vendor "Redmine" for product "Redmine" and version "0.7.1"
-
Affected
Redmine
Search vendor "Redmine"
Redmine
Search vendor "Redmine" for product "Redmine"
0.7.2
Search vendor "Redmine" for product "Redmine" and version "0.7.2"
-
Affected
Redmine
Search vendor "Redmine"
Redmine
Search vendor "Redmine" for product "Redmine"
0.7.3
Search vendor "Redmine" for product "Redmine" and version "0.7.3"
-
Affected
Redmine
Search vendor "Redmine"
Redmine
Search vendor "Redmine" for product "Redmine"
0.7.4
Search vendor "Redmine" for product "Redmine" and version "0.7.4"
-
Affected
Redmine
Search vendor "Redmine"
Redmine
Search vendor "Redmine" for product "Redmine"
0.8.0
Search vendor "Redmine" for product "Redmine" and version "0.8.0"
-
Affected
Redmine
Search vendor "Redmine"
Redmine
Search vendor "Redmine" for product "Redmine"
0.8.0
Search vendor "Redmine" for product "Redmine" and version "0.8.0"
rc1
Affected
Redmine
Search vendor "Redmine"
Redmine
Search vendor "Redmine" for product "Redmine"
0.8.1
Search vendor "Redmine" for product "Redmine" and version "0.8.1"
-
Affected
Redmine
Search vendor "Redmine"
Redmine
Search vendor "Redmine" for product "Redmine"
0.8.2
Search vendor "Redmine" for product "Redmine" and version "0.8.2"
-
Affected
Redmine
Search vendor "Redmine"
Redmine
Search vendor "Redmine" for product "Redmine"
0.8.3
Search vendor "Redmine" for product "Redmine" and version "0.8.3"
-
Affected
Redmine
Search vendor "Redmine"
Redmine
Search vendor "Redmine" for product "Redmine"
0.8.4
Search vendor "Redmine" for product "Redmine" and version "0.8.4"
-
Affected
Redmine
Search vendor "Redmine"
Redmine
Search vendor "Redmine" for product "Redmine"
0.8.5
Search vendor "Redmine" for product "Redmine" and version "0.8.5"
-
Affected
Redmine
Search vendor "Redmine"
Redmine
Search vendor "Redmine" for product "Redmine"
0.8.6
Search vendor "Redmine" for product "Redmine" and version "0.8.6"
-
Affected