CVE-2009-3486
CVSS V2 Low 3.5
CVSS V3 None
Description
Multiple cross-site scripting (XSS) vulnerabilities in the J-Web interface in Juniper JUNOS 8.5R1.14 allow remote authenticated users to inject arbitrary web script or HTML via the host parameter to (1) the pinghost program, reachable through the diagnose program; or (2) the traceroute program, reachable through the diagnose program; or (3) the probe-limit parameter to the configuration program; the (4) wizard-ids or (5) pager-new-identifier parameter in a firewall-filters action to the configuration program; (6) the cos-physical-interface-name parameter in a cos-physical-interfaces-edit action to the configuration program; the (7) wizard-args or (8) wizard-ids parameter in an snmp action to the configuration program; the (9) username or (10) fullname parameter in a users action to the configuration program; or the (11) certname or (12) certbody parameter in a local-cert (aka https) action to the configuration program.
Overview
- CVE ID
- CVE-2009-3486
- Assigner
- cve@mitre.org
- Vulnerability Status
- Analyzed
- Published Version
- 2009-09-30T15:30:00
- Last Modified Date
- 2009-10-05T04:00:00
Weakness Enumerations
CPE Configuration (Product)
CPE | Vulnerable | Operator | Version Start | Version End |
---|---|---|---|---|
cpe:2.3:o:juniper:junos:8.5:r1.14:*:*:*:*:*:* | 1 | OR |
CVSS Version 2
- Version
- 2.0
- Vector String
- AV:N/AC:M/Au:S/C:N/I:P/A:N
- Access Vector
- NETWORK
- Access Compatibility
- MEDIUM
- Authentication
- SINGLE
- Confidentiality Impact
- NONE
- Integrity Impact
- PARTIAL
- Availability Impact
- NONE
- Base Score
- 3.5
- Severity
- LOW
- Exploitability Score
- 6.8
- Impact Score
- 2.9
References
Reference URL | Reference Tags |
---|---|
http://www.vupen.com/english/advisories/2009/2784 | Vendor Advisory |
http://secunia.com/advisories/36829 | Vendor Advisory |
http://www.procheckup.com/vulnerability_manager/vulnerabilities/pr09-09 | Exploit |
http://www.securityfocus.com/bid/36537 | Exploit |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2009-3486 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3486 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2022-05-10 11:13:37 | Added to TrackCVE |