← Back

CVE-2009-1294

nvd nist
Published: Apr 16, 2009Modified: Apr 23, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:N/I:P/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

Multiple cross-site scripting (XSS) vulnerabilities in web/guest/home in the Liferay 4.3.0 portal in Novell Teaming 1.0 through SP3 (1.0.3) allow remote attackers to inject arbitrary web script or HTML via the (1) p_p_state or (2) p_p_mode parameters.

Affected (5)

1 product
Teaming
1 product
Liferay Enterprise Portal
Configuration A
5 vulnerable
Vulnerable SoftwareAffected Versions
Novell
Version 1.0.1
Version 1.0.2
Version 1.0.3
Version 1.0
Version 4.3.0

Timeline

No history available yet.