← Back

CVE-2009-1288

nvd nist
Published: Apr 13, 2009Modified: Apr 23, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:N/I:P/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

Multiple cross-site scripting (XSS) vulnerabilities in the Advanced Management Module (AMM) on the IBM BladeCenter, including the BladeCenter H with BPET36H 54, allow remote attackers to inject arbitrary web script or HTML via (1) the username in a login action or (2) the PATH parameter to private/file_management.ssi in the File manager.

Affected (30)

2 products
Advanced Management Module
Bladecenter
Configuration A
30 vulnerable
Vulnerable SoftwareAffected Versions
Version 1.36h
Ibm
Version e
Version e
Version e
Version h
Version h
Version hc10
Version hs12
Version hs12
Version hs12
Version hs20
Version hs21
Version hs21
Version hs21_xm
Version hs21_xm
Version ht
Version ht
Version js12
Version js21
Version js21
Version js22
Version ls20
Version ls21
Version ls41
Version qs21
Version qs22
Version s
Version s
Version t
Version t

References (12)

Source: cve@mitre.org
Source: cve@mitre.org
Source: cve@mitre.org
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit

Timeline

No history available yet.